Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f39f0d0b0063e35…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 02:48:04 +01:00 Authoring application: mPDF 5.7
MD5: d41134f2cba7fbdca82d7b12d7cb01dc SHA-1: cbbcd070d0bae14306f75b4b790f67e37cfcd2a7 SHA-256: 0f39f0d0b0063e351937aa075207fec525eaee218fecbe0b6ce3cce71d840182
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF was flagged by a machine learning classifier and contains a large number of embedded URLs, many of which are dynamically generated and point to external PDF files. This behavior is indicative of a link farm or a method to distribute further malicious content, likely delivered via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1095094091093098/The-Mainspring-of-Human-Progress-by-Henry-Grady-Weaver.pdf
    • http://loaminoo.linkpc.net/3095090091094090/My-Pilgrim-s-Progress-Media-Studies-1950-1998-by-George-W-S-Trow.pdf
    • http://loaminoo.linkpc.net/9090092091090098/The-Origin-Progress-and-Difficulties-of-the-Achill-Mission-As-Detailed-in-the-Minutes-of-Evidence-Taken-Before-the-Select-Committee-of-the-House-of-Lords-Appointed-to-Inquire-Into-the-Progress-and-Operation-of-the-New-Plan-of-Education-in-Ireland-And-by-Edward-Nangle.pdf
    • http://loaminoo.linkpc.net/2095091099099097/The-Autobiography-Of-Henry-VIII-by-Margaret-George.pdf
    • http://loaminoo.linkpc.net/3090096093097091/Witch-Queen-of-Lochlann-by-George-Henry-Smith.pdf
    • http://loaminoo.linkpc.net/5092093093097099/Hubert-Hervey-Student-and-Imperialist-A-Memoir-by-Albert-Henry-George-Grey.pdf
    • http://loaminoo.linkpc.net/7096093091090091/En-Avant-Messieurs-Being-a-Tutor-s-Counsel-to-His-Pupils-by-George-Henry-Duncan-1833--1869-Mathias.pdf
    • http://loaminoo.linkpc.net/9093094090095/Progress-Progress-1-by-Amy-Queau.pdf
    • http://loaminoo.linkpc.net/3093099098098093/Fatal-Rivalry-Flodden-1513-Henry-VIII-and-James-IV-and-the-Decisive-Battle-for-Renaissance-Britain-by-George-Goodwin.pdf
    • http://loaminoo.linkpc.net/9097097099090094/Geopoliticians-Henry-Kissinger-Zbigniew-Brzezinski-Samuel-P-Huntington-Karl-Haushofer-Sven-Hedin-George-F-Kennan-Carl-Schmitt-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/6098096097092090/Poverty-by-Alan-Dures.pdf
    • http://loaminoo.linkpc.net/9099090093091/The-End-of-Poverty-by-Jeffrey-D-Sachs.pdf
    • http://loaminoo.linkpc.net/4090094096095098/See-Poverty-Be-The-Difference-by-Donna-Beegle.pdf
    • http://loaminoo.linkpc.net/1093092096096095/Poverty-Safari-by-Darren-McGarvey.pdf
    • http://loaminoo.linkpc.net/1094094095093091/Out-of-Poverty-And-Into-Something-More-Comfortable-by-John-Stackhouse.pdf
    • http://loaminoo.linkpc.net/1098095099099091/Escaping-Poverty-by-Reading-Harbor.pdf
    • http://loaminoo.linkpc.net/3096091096097094/A-Poverty-of-Words-by-Frederick-Pollack.pdf
    • http://loaminoo.linkpc.net/1099093094092093/Street-Angel-The-Princess-of-Poverty-by-Jim-Rugg.pdf
    • http://loaminoo.linkpc.net/4091099091099097/-1-Binbougami-ga-The-God-of-Poverty-Is-1-by-Yoshiaki-Sukeno.pdf
    • http://loaminoo.linkpc.net/1091096093096092095/Endymion-a-Tale-of-Greece-by-Henry-B-Henry-Beck-1813-1874-Hirst.pdf