Malicious PDF — malware analysis report

Static analysis result for SHA-256 0c5c2815cb7a1fd8…

MALICIOUS

PDF

18.2 KB Created: 2019-04-30 09:42:27 +01:00 Authoring application: mPDF 5.7
MD5: 9b799a760c99354e513fa72edc73eeaf SHA-1: cc6ee5ffb740b0691969ed7f88fb58417b0cf741 SHA-256: 0c5c2815cb7a1fd87b541cc99138b0d42ba38f4e1e0579c92ae168a124055eae
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, each pointing to a PDF file with a book title as its slug. This pattern is indicative of a link farm designed to generate traffic or potentially distribute further malicious content. While no scripts were extracted, the PDF structure and embedded URLs strongly suggest a malicious intent to redirect users to external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9095094095/All-That-Heaven-Allows-A-Biography-of-Rock-Hudson-by-Mark-Griffin.pdf
    • http://loaminoo.linkpc.net/2091097095092/From-Bondage-by-Henry-Roth.pdf
    • http://loaminoo.linkpc.net/5094091097099090/Much-ADO-about-Nothing-Annotated-by-Henry-N-Hudson-with-an-Introduction-by-Charles-Harold-Herford-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/1097097098097092/Henry-Potty-and-the-Pet-Rock-An-Unauthorized-Harry-Potter-Parody-by-Valerie-Estelle-Frankel.pdf
    • http://loaminoo.linkpc.net/5093095099097095/Kiera-Hudson-amp-The-Final-Push-Kiera-Hudson-Series-Three-Book-7-by-Tim-O-39-Rourke.pdf
    • http://loaminoo.linkpc.net/5093095099094092/Kiera-Hudson-amp-The-Origins-of-Cara-Kiera-Hudson-Series-Three-6-by-Tim-O-39-Rourke.pdf
    • http://loaminoo.linkpc.net/5093095099093099/Kiera-Hudson-amp-The-Secret-Identity-Kiera-Hudson-Series-Three-4-by-Tim-O-39-Rourke.pdf
    • http://loaminoo.linkpc.net/9091098094094095/Joseph-Roth---Gesammelte-Werke-Romane-Erz-hlungen-Journalistische-Schriften-mehr-als-30-Titel-in-einem-E-Book---Radetzkymarsch-Hiob-Die-Kapuzinergruft-Trinker-Das-falsche-Gewic-by-Joseph-Roth.pdf
    • http://loaminoo.linkpc.net/6099094099094098/Philip-Roth-Reads-from-His-Zuckerman-Bound-by-Philip-Roth.pdf
    • http://loaminoo.linkpc.net/1091092097098091/The-World-of-Veronica-Roth-s-Divergent-Series-by-Veronica-Roth.pdf
    • http://loaminoo.linkpc.net/5096097097096/Diving-In-Art-amp-Coll-1-by-Kate-Cann.pdf
    • http://loaminoo.linkpc.net/1091093090096093/Diving-Belles-by-Lucy-Wood.pdf
    • http://loaminoo.linkpc.net/8091092099095097/The-Diving-Bell-by-Todd-Strasser.pdf
    • http://loaminoo.linkpc.net/1091093092098095092/Diving-in-Resort-to-Love-2-by-Gretchen-Galway.pdf
    • http://loaminoo.linkpc.net/7090090096094/The-Diving-Pool-Three-Novellas-by-Y-ko-Ogawa.pdf
    • http://loaminoo.linkpc.net/7091090091099/Dreams-of-Sex-and-Stage-Diving-by-Martin-Millar.pdf
    • http://loaminoo.linkpc.net/9098091099098095/Eiskalte-See-Diving-Hunters-by-Leocardia-Sommer.pdf
    • http://loaminoo.linkpc.net/9092096092091098/Psychological-And-Behavioral-Aspects-Of-Diving-by-Baruch-Nevo.pdf
    • http://loaminoo.linkpc.net/2095094099090090/Diving-for-Sunken-Treasure-by-Jacques-Yves-Cousteau.pdf
    • http://loaminoo.linkpc.net/6090097099097091/Diving-with-Body-Mind-and-Emotions-by-Monika-Rahimi.pdf