Malicious PDF — malware analysis report

Static analysis result for SHA-256 0feeb0634a85c2d1…

MALICIOUS

PDF

19.9 KB Created: 2019-04-30 04:15:26 +01:00 Authoring application: mPDF 5.7
MD5: 7619f795f0bf45b0479d233141be1999 SHA-1: e0b856a67aae341ed2d5fac72831e9b92e7ed98f SHA-256: 0feeb0634a85c2d178b7109a903922b6ed065284fd992429284e2533338800d9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, suggesting a link farm or SEO poisoning attempt. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a large collection of external documents hosted on a dynamic DNS domain, likely to distribute unwanted content or for SEO manipulation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6092092095090095/Mind-Matters-Book-1-Confusion-by-Toni-Plaisir.pdf
    • http://loaminoo.linkpc.net/6092092094099096/Groomed-Cuckold-by-Toni-Plaisir.pdf
    • http://loaminoo.linkpc.net/4092093099090099/Your-Mind-Matters-The-Place-of-the-Mind-in-the-Christian-Life-by-John-R-W-Stott.pdf
    • http://loaminoo.linkpc.net/1094096097090091/All-that-Matters-Family-Matters-Book-2-by-Liana-Key.pdf
    • http://loaminoo.linkpc.net/3096099091099092/A-Mind-for-What-Matters-Collected-Essays-by-F-F-Bruce.pdf
    • http://loaminoo.linkpc.net/5098098094093091/Volcaniques-Une-anthologie-du-plaisir-Une-anthologie-du-plaisir-by-L-onora-Miano.pdf
    • http://loaminoo.linkpc.net/6091091099092090/Cien-Anos-De-Confusion-One-Hundred-Years-Of-Confusion-Mexico-En-El-Siglo-Xx-Mexico-In-The-Twentieth-Century-by-Macario-Schettino.pdf
    • http://loaminoo.linkpc.net/2098095093092096/The-Confusion-Part-I-The-Baroque-Cycle-Vol-2-Book-1-by-Neal-Stephenson.pdf
    • http://loaminoo.linkpc.net/6091091097098094/The-Confusion-Part-II-The-Baroque-Cycle-Vol-2-Book-2-by-Neal-Stephenson.pdf
    • http://loaminoo.linkpc.net/5098099097095/Mike-Nelson-s-Mind-over-Matters-by-Michael-J-Nelson.pdf
    • http://loaminoo.linkpc.net/1091094092090094097/The-Art-of-Belief-Design-Your-Mind-to-Destroy-Limitations-Unleash-Inner-Greatness-and-Create-the-Life-of-Your-Dreams-Success-Mindset-Mind-Development-Thought-Power-Book-1-by-Stellan-Moreira.pdf
    • http://loaminoo.linkpc.net/9096094099099097/Mind-Games---A-Bad-Boy-Romance-With-A-Twist-Mind-Games-Book-2-by-Gabi-Moore.pdf
    • http://loaminoo.linkpc.net/1092090096092095/Pink-Matters-Angelic-Matters-1-by-Olga-N-ez-Miret.pdf
    • http://loaminoo.linkpc.net/2096097090092094/Balancing-Act---a-Kovak-amp-Quaid-Horse-Mystery-Book-2-by-Toni-Leland.pdf
    • http://loaminoo.linkpc.net/9098091098099/Why-To-Kill-a-Mockingbird-Matters-What-Harper-Lee-s-Book-and-America-s-Iconic-Film-Mean-to-Us-Today-by-Tom-Santopietro.pdf
    • http://loaminoo.linkpc.net/6094095095091091/Felure-Du-Plaisir-by-Monique-Dixsaut.pdf
    • http://loaminoo.linkpc.net/2095095090094095/Quotes-Of-Wisdom-To-Live-By-Pearls-of-Wisdom-Quotes-for-the-Body-Mind-and-Soul-Self-Help-Spiritual-and-Personal-Growth-Book-Book-3-by-Brian-Michael-Good.pdf
    • http://loaminoo.linkpc.net/1091094097090095099/Toni-May-Kolner-Kopfe-Kolner-Skizzen-by-Toni-May.pdf
    • http://loaminoo.linkpc.net/8090096095097097/Je-prends-beaucoup-de-plaisir-tromper-mon-mari-by-Solange-W-C-.pdf
    • http://loaminoo.linkpc.net/5090095098099098/A-Book-of-Light-When-a-Loved-One-Has-a-Different-Mind-by-Jerry-Pinto.pdf