Malicious PDF — malware analysis report

Static analysis result for SHA-256 133328539d03b6d9…

MALICIOUS

PDF

13.0 KB Created: 2019-04-30 04:40:19 +01:00 Authoring application: mPDF 5.7
MD5: e875fc9d89e254a1db0383ca370c4931 SHA-1: 07664a2ea849ef86072a419ac16f822441af7c29 SHA-256: 133328539d03b6d9b36c615f2caf60e8c4f27a476925042d572c8003efef74cb
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to other PDF files hosted on a dynamic DNS domain, indicative of a link farm. While the ML classifier flagged this as malicious, the specific intent appears to be driving traffic to these external resources rather than executing a direct payload from this file. The heuristic PDF_SEO_LINK_FARM strongly suggests this behavior.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9006

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099094097097097/The-Other-Inheritance-Inheritance-1-by-Rebecca-Jaycox.pdf
    • http://loaminoo.linkpc.net/5096094092093094/de-Pourpre-Et-de-Soleil-by-Kate-Bowes.pdf
    • http://loaminoo.linkpc.net/2092090093096093/One-Heartbeat-The-Hana-Du-Rose-Mysteries-5-by-K-T-Bowes.pdf
    • http://loaminoo.linkpc.net/4094094092093092/Whilst-the-Mountains-Slept-by-Simon-Bowes-Charles.pdf
    • http://loaminoo.linkpc.net/3095093092095094/The-New-Du-Rose-Matriarch-The-Hana-Du-Rose-Mysteries-4-by-K-T-Bowes.pdf
    • http://loaminoo.linkpc.net/3095093093099096/Du-Rose-Legacy-The-Hana-Du-Rose-Mysteries-3-by-K-T-Bowes.pdf
    • http://loaminoo.linkpc.net/8092090099096095/The-Inheritance-by-Mika-Lane.pdf
    • http://loaminoo.linkpc.net/2092091090098096/The-Inheritance-by-Robin-Hobb.pdf
    • http://loaminoo.linkpc.net/1091090092092/The-Inheritance-by-Tamera-Alexander.pdf
    • http://loaminoo.linkpc.net/6096092098091091/Inheritance-by-Christopher-Paolini.pdf
    • http://loaminoo.linkpc.net/1092092096092094/The-Inheritance-by-Irina-Shapiro.pdf
    • http://loaminoo.linkpc.net/3099098093094091/The-Inheritance-by-Irina-Shapiro.pdf
    • http://loaminoo.linkpc.net/5090093096095091/The-Inheritance-by-Louisa-May-Alcott.pdf
    • http://loaminoo.linkpc.net/2091094091099098/The-Awakened-Kingdom-Inheritance-3-5-by-N-K-Jemisin.pdf
    • http://loaminoo.linkpc.net/3095099093091092/Rendezvous-in-Rio-The-Inheritance-2-by-Danielle-Bourdon.pdf
    • http://loaminoo.linkpc.net/2091092093099/The-Inheritance-of-Loss-by-Kiran-Desai.pdf
    • http://loaminoo.linkpc.net/4097091090091094/Family-Inheritance-by-Deborah-Leblanc.pdf
    • http://loaminoo.linkpc.net/2099099091096097/Eragon-Inheritance-1-by-Christopher-Paolini.pdf
    • http://loaminoo.linkpc.net/1090098090093091093/Prince-With-No-Inheritance-by-Toban-Schreyer.pdf
    • http://loaminoo.linkpc.net/1093094092094097/Inheritance-by-Tara-Palmer-Tomkinson.pdf