Malicious PDF — malware analysis report

Static analysis result for SHA-256 09341090e5fa72de…

MALICIOUS

PDF

20.3 KB Created: 2019-05-04 14:42:20 +01:00 Authoring application: mPDF 5.7
MD5: a80aafc16196e2bb9453f864737d7693 SHA-1: 0fcb8d09501667fd94678c3042ea5c318db9fa4c SHA-256: 09341090e5fa72de5ddeb9dd3fca840461ecc9b373f8b14f286c8f487278fab4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6093097096099094/Smart-Policies-for-Workplace-Technology-Email-Blogs-Cell-Phones-amp-More-With-CDROM-by-Lisa-Guerin.pdf
    • http://loaminoo.linkpc.net/6093097096092090/The-Essential-Guide-to-Workplace-Investigations-With-CDROM-by-Lisa-Guerin.pdf
    • http://loaminoo.linkpc.net/6093097096091093/Create-Your-Own-Employee-Handbook-A-Legal-amp-Practical-Guide-for-Employers-With-CDROM-by-Lisa-Guerin.pdf
    • http://loaminoo.linkpc.net/9097093097099090/Buy-It-Right-Cell-Phones-and-Plans-by-Joni-Blecher.pdf
    • http://loaminoo.linkpc.net/1098094097094095/Email-Marketing-Effective-Email-Marketing-The-Ultimate-Guide-to-Monetizing-Your-Email-Marketing-Strategy-by-Sam-A-Brown.pdf
    • http://loaminoo.linkpc.net/6093097097090094/A-Culture-of-Light-Cinema-and-Technology-in-1920s-Germany-by-Frances-Guerin.pdf
    • http://loaminoo.linkpc.net/1099095090090097/Love-at-the-Speed-of-Email-by-Lisa-McKay.pdf
    • http://loaminoo.linkpc.net/7091090094094097/Email-Persuasion-Captivate-and-Engage-Your-Audience-Build-Authority-and-Generate-More-Sales-With-Email-Marketing-by-Ian-Brodie.pdf
    • http://loaminoo.linkpc.net/5098096096094091/Small-Cell-and-CRAN-Report-Wireless-Technology-Update-by-Wade-Sarver.pdf
    • http://loaminoo.linkpc.net/6093097096091097/Employment-Law-The-Essential-HR-Desk-Reference-by-Lisa-Guerin.pdf
    • http://loaminoo.linkpc.net/6093097097096090/Essential-Guide-to-Family-amp-Medical-Leave-by-Lisa-Guerin.pdf
    • http://loaminoo.linkpc.net/6093097097097094/Protecting-Your-Factory-from-Fire-A-Manual-of-Fire-Prevention-for-Industrial-Plants-by-Guerin-Guerin.pdf
    • http://loaminoo.linkpc.net/5097093092094098/Cell-to-Cell-Signals-in-Plants-and-Animals-Progress-Report-by-Volker-Ed-Neuhoff.pdf
    • http://loaminoo.linkpc.net/8090099093099097/Smart-Talk-The-Public-Speaker-s-Guide-to-Success-in-Every-Situation-by-Lisa-B-Marshall.pdf
    • http://loaminoo.linkpc.net/6093097096092091/Lake-Guerin-Fun-Book-A-Fun-and-Educational-Book-about-Lake-Guerin-by-Jobe-Leonard.pdf
    • http://loaminoo.linkpc.net/2099099099/Are-We-Smart-Enough-to-Know-How-Smart-Animals-Are-by-Frans-de-Waal.pdf
    • http://loaminoo.linkpc.net/8095090090099099/Free-Technology-for-Libraries-Library-Technology-Essentials-by-Amy-Deschenes.pdf
    • http://loaminoo.linkpc.net/1090095097094090095/The-4-1-1-on-Phones-by-Kama-Einhorn.pdf
    • http://loaminoo.linkpc.net/6094098098094098/The-Eagle-Has-Landed-With-Ear-Phones-by-Jack-Higgins.pdf
    • http://loaminoo.linkpc.net/1095093095098096/Love-Me-If-You-Dare-Bachelor-Blogs-2-by-Carly-Phillips.pdf