Malicious PDF — malware analysis report

Static analysis result for SHA-256 142892ee0411bc97…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 05:27:30 +01:00 Authoring application: mPDF 5.7
MD5: 288fc2e7a1dc1d816ae2c916166c0fb6 SHA-1: 36088552cc1238f2bbfaf3ffb01af4cd6581fcfd SHA-256: 142892ee0411bc97df664e193db257f53816609d788c9a94ccb6dbb6f0377651
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6093092093092090/The-Mortal-Instruments-Companion-City-of-Bones-Shadowhunters-and-the-Sight-The-Unauthorized-Guide-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/4098095099091093/City-of-Bones-Shadowhunters-The-Mortal-Instruments-1-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/1090093091091091092/The-Divergent-Companion-The-Unauthorized-Guide-to-the-Series-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/3092095090090/The-Mortal-Instruments-Boxed-Set-City-of-Bones-City-of-Ashes-City-of-Glass-The-Mortal-Instruments-1-3-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/4098093094096091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/3097096090091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/1091093096097090099/The-Ultimate-Unauthorized-Eragon-Guide-The-Hidden-Facts-Behind-the-World-of-Alagaesia-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/5098091099095/City-of-Bones-The-Mortal-Instruments-1-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/5099093090091093/City-of-Bones-The-Mortal-Instruments-1-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/2096097092092/City-of-Bones-The-Mortal-Instruments-1-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/3093090090092096/The-Mortal-Instruments-City-of-Bones-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/4092098098096099/City-of-Ashes-The-Mortal-Instruments-2-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/2097097092093098/City-of-Glass-The-Mortal-Instruments-3-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/3097093096091091/City-of-Fallen-Angels-The-Mortal-Instruments-4-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/1091096097093095/City-of-Fallen-Angels-The-Mortal-Instruments-4-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/6096094091097095/City-of-Heavenly-Fire-The-Mortal-Instruments-6-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/3099099094090/City-of-Heavenly-Fire-The-Mortal-Instruments-6-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/2099091094094095/The-Science-of-Superheroes-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/1091091090091090093/Haunted-City-An-Unauthorized-Guide-to-the-Magical-Magnificent-New-Orleans-of-Anne-Rice-by-Joy-Dickinson.pdf
    • http://loaminoo.linkpc.net/3091099098090099/Exploring-Philip-Pullman-s-His-Dark-Materials-by-Lois-H-Gresh.pdf