Malicious PDF — malware analysis report

Static analysis result for SHA-256 0fd7fe9c611208c3…

MALICIOUS

PDF

19.8 KB Created: 2019-04-30 09:42:14 +01:00 Authoring application: mPDF 5.7
MD5: 0e5932381b5c7aeeea600b5d72811d65 SHA-1: 1444b69220a0205cdbafd695a995d30c173db128 SHA-256: 0fd7fe9c611208c320cc6066eb1596adcf24643e276ddcd83a5b1777d325cf9f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently flagged as benign, the sheer volume and the heuristic 'PDF_SEO_LINK_FARM' suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096091095092099/The-Apocalypse-Sacrifice-The-Undead-World-10-by-Peter-Meredith.pdf
    • http://loaminoo.linkpc.net/3095099092090097/The-Apocalypse-The-Undead-World-1-by-Peter-Meredith.pdf
    • http://loaminoo.linkpc.net/4090096093095093/Zombie-Apocalypse-Preparation-How-to-Survive-in-an-Undead-World-and-Have-Fun-Doing-It-by-David-Houchins.pdf
    • http://loaminoo.linkpc.net/3096090093092092/Mad-About-Undead-You-A-Zombie-Apocalypse-Love-Story-by-Carl-S-Plumer.pdf
    • http://loaminoo.linkpc.net/7090099099096090/Novels-by-Maryjanice-Davidson-Undead-and-Unappreciated-Derik-s-Bane-Undead-and-Unreturnable-Undead-and-Unwed-Swimming-Without-a-Net-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/2092090094096096/Apocalypse-Mom-Diary-of-an-Ordinary-Woman-in-a-Not-So-Ordinary-World-Apocalypse-Mom-Series-1-by-Elizabeth-L-Jones.pdf
    • http://loaminoo.linkpc.net/7091093094092099/Sprite-by-Peter-Meredith.pdf
    • http://loaminoo.linkpc.net/6090092099094092/The-Fourth-Sacrifice-China-Thrillers-2-by-Peter-May.pdf
    • http://loaminoo.linkpc.net/1097097091092099/Undead-to-the-World-The-Bloodhound-Files-6-by-D-D-Barant.pdf
    • http://loaminoo.linkpc.net/9099092097090094/Vampire-The-Complete-Guide-to-the-World-of-the-Undead-by-Manuela-Dunn-Mascetti.pdf
    • http://loaminoo.linkpc.net/4098096092091/The-Pearl-of-the-Soul-of-the-World-Darkangel-Trilogy-3-by-Meredith-Ann-Pierce.pdf
    • http://loaminoo.linkpc.net/6093093093092099/The-Most-Fabulous-Jewels-in-the-World-Graff-by-Meredith-Etherington-Smith.pdf
    • http://loaminoo.linkpc.net/2091092090092099/The-Pearl-of-the-Soul-of-the-World-Darkangel-Trilogy-3-by-Meredith-Ann-Pierce.pdf
    • http://loaminoo.linkpc.net/2097090091098095/Live-Undead-The-Undead-Chronicles-1-by-Steve-Warren.pdf
    • http://loaminoo.linkpc.net/4090097090096097/The-Old-Man-at-the-End-of-the-World-No-1-Note-the-apocalypse-isn-t-really-going-to-happen-by-A-K-Silversmith.pdf
    • http://loaminoo.linkpc.net/4091099090094093/The-Undead-World-of-Oz-L-Frank-Baum-s-the-Wonderful-Wizard-of-Oz-Complete-with-Zombies-and-Monsters-by-Ryan-C-Thomas.pdf
    • http://loaminoo.linkpc.net/3093096094096/Undead-and-Unwed-Undead-1-by-MaryJanice-Davidson.pdf
    • http://loaminoo.linkpc.net/1096095096097096/Undead-and-Uneasy-Undead-6-by-MaryJanice-Davidson.pdf
    • http://loaminoo.linkpc.net/1093095090093097/The-Undead-Situation-Undead-1-by-Eloise-J-Knapp.pdf
    • http://loaminoo.linkpc.net/1093096091096090/Undead-and-Unstable-Undead-11-by-MaryJanice-Davidson.pdf