Malicious PDF — malware analysis report

Static analysis result for SHA-256 0ceff8991f527a70…

MALICIOUS

PDF

21.7 KB Created: 2019-04-30 05:26:31 +01:00 Authoring application: mPDF 5.7
MD5: 3ed257ee28dda603a0b77893492e0b5b SHA-1: 7fb280f9b1dec124e89ab208b54ffc32c33ceff1 SHA-256: 0ceff8991f527a703ca0e92c61da02b895527ad53e62ed28065fed464f308d6f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a malicious intent to manipulate search engine results or distribute malware. While the document body is unreadable, the presence of numerous external links points towards a phishing or SEO spam attack. No scripts were extracted, but the structure indicates a potential for malicious redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090099092099090094/Florida-Sinkholes-Science-and-Policy-by-Robert-Brinkmann.pdf
    • http://loaminoo.linkpc.net/9099090099092/The-New-Deal-in-South-Florida-Design-Policy-and-Community-Building-1933-1940-by-John-A-Stuart.pdf
    • http://loaminoo.linkpc.net/1090099092099090091/Psychology-as-a-Moral-Science-Perspectives-on-Normativity-by-Svend-Brinkmann.pdf
    • http://loaminoo.linkpc.net/4096095096095095/Poverty-and-Public-Policy-An-Evaluation-of-Social-Science-Research-by-Vincent-Covello.pdf
    • http://loaminoo.linkpc.net/5090090096095090/Riding-the-Florida-Time-Line-by-Robert-Lee-Thompson.pdf
    • http://loaminoo.linkpc.net/6090099093092094/Your-Guide-to-Florida-Property-Investment-for-Global-Buyers-Owning-Investing-and-Enjoying-the-Florida-Lifestyle-by-Lee-Mirman.pdf
    • http://loaminoo.linkpc.net/9099095091090093/The-Economic-Policy-of-Robert-Walpole-by-Norris-Arthur-Brisco.pdf
    • http://loaminoo.linkpc.net/6099096092097097/The-First-Science-Fiction-MEGAPACK-25-Modern-and-Classic-Science-Fiction-Tales-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/5091099098093098/Access-Points-An-Institutional-Theory-of-Policy-Bias-and-Policy-Complexity-by-Sean-D-Ehrlich.pdf
    • http://loaminoo.linkpc.net/7092094096090/An-Introduction-to-the-Policy-Process-Theories-Concepts-and-Models-of-Public-Policy-Making-by-Thomas-A-Birkland.pdf
    • http://loaminoo.linkpc.net/2090098093098098/Off-the-Main-Sequence-The-Other-Science-Fiction-Stories-of-Robert-A-Heinlein-by-Robert-A-Heinlein.pdf
    • http://loaminoo.linkpc.net/2096096095096/The-Science-Fiction-Hall-of-Fame-Volume-One-1929-1964-Science-Fiction-Hall-of-Fame-1-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/8092096099096094/Fundamentals-of-Weed-Science-by-Robert-L-Zimdahl.pdf
    • http://loaminoo.linkpc.net/8097094091098094/Case-Studies-In-Environmental-Science-by-Robert-M-Schoch.pdf
    • http://loaminoo.linkpc.net/4094097092097094/Science-Matters-Achieving-Scientific-Literacy-by-Robert-M-Hazen.pdf
    • http://loaminoo.linkpc.net/4094097094092093/Being-Human-Life-Lessons-from-the-Frontiers-of-Science-by-Robert-M-Sapolsky.pdf
    • http://loaminoo.linkpc.net/1096093091098096/Great-Science-Fiction-of-the-20th-Century-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/2093099094098095/Voodoo-Science-The-Road-from-Foolishness-to-Fraud-by-Robert-L-Park.pdf
    • http://loaminoo.linkpc.net/2096095095091/Far-Horizons-All-New-Tales-from-the-Greatest-Worlds-of-Science-Fiction-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/3096096096095092/Why-Buddhism-is-True-The-Science-and-Philosophy-of-Meditation-and-Enlightenment-by-Robert-Wright.pdf