Malicious PDF — malware analysis report

Static analysis result for SHA-256 09a37f6b921b151a…

MALICIOUS

PDF

12.7 KB Created: 2019-04-29 23:02:25 +01:00 Authoring application: mPDF 5.7
MD5: 7c6dae33f8dd60dd1d29487c65e3e960 SHA-1: e04fe68af77110b452e3feae8af701144b34fe2c SHA-256: 09a37f6b921b151a6aa29cc42aa4d46434631d9dda22db7bad51b8a3ea0112bd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, hosted on a dynamic DNS domain. This pattern is indicative of a link farm or SEO poisoning campaign, designed to drive traffic to malicious or low-quality content. While no scripts were explicitly extracted, the PDF structure and the heuristic firings suggest an attempt to manipulate search engine results or distribute further content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8780

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090095091095099/Raft-Xeelee-Sequence-1-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/2098091092091091/Ultima-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/9094093096094/Evolution-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/1096091093091097/Flood-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/1096093099098098/The-Wheel-of-Ice-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/4094097094095093/Ark-Flood-2-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/1090093098098099/Proxima-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/4091099090097090/Anti-Ice-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/2094099091094/The-Time-Ships-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/4091090096096092/The-Science-of-Avatar-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/4098095099093092/The-Massacre-of-Mankind-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/3096097096093091/Bronze-Summer-Northland-2-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/6097091095097/Coalescent-Destiny-s-Children-1-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/1096091096090096/Exultant-Destiny-s-Children-2-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/3092099092090090/Moonseed-NASA-Trilogy-3-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/6093095094098096/Doctor-Who---La-Roue-de-Glace-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/7090097090090/Manifold-Space-Manifold-2-by-Stephen-Baxter.pdf
    • http://loaminoo.linkpc.net/1090091097090097093/Buck-Baxter-Love-Detective-The-Buck-Baxter-Mysteries-1-by-Geoffrey-Knight.pdf
    • http://loaminoo.linkpc.net/9097093097099093/The-Hilbert-Moore-Sequence-the-Hilbert-Moore-Sequence-by-Wolf-Blecher.pdf
    • http://loaminoo.linkpc.net/3096097095097096/Raft-People-by-M-L-Katz.pdf