Malicious PDF — malware analysis report

Static analysis result for SHA-256 16c26e80a459ba21…

MALICIOUS

PDF

19.2 KB Created: 2019-04-29 23:34:27 +01:00 Authoring application: mPDF 5.7
MD5: ff050e882adf1032c03b28cf6485d9d0 SHA-1: cc0dba7b88b01d72ae2ccc434962625547c6432b SHA-256: 16c26e80a459ba2150bd12f4dfed8e7890c6174c904c642bc689b295d5dfc00d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links, such as http://loaminoo.linkpc.net/1095095096093094/The-Sodom-and-Gomorrah-Business-by-Barry-N-Malzberg.pdf, are presented in a way that suggests a link farm or a deceptive lure. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. No scripts were extracted, but the structure indicates a likely attempt to redirect users to external, potentially malicious, content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1095095096093094/The-Sodom-and-Gomorrah-Business-by-Barry-N-Malzberg.pdf
    • http://loaminoo.linkpc.net/1097095097096091/Galaxies-by-Barry-N-Malzberg.pdf
    • http://loaminoo.linkpc.net/1097097091095090/Phase-IV-by-Barry-N-Malzberg.pdf
    • http://loaminoo.linkpc.net/1090093097096093/Beyond-Apollo-by-Barry-N-Malzberg.pdf
    • http://loaminoo.linkpc.net/3092091097093097/The-Best-Time-Travel-Stories-of-All-Time-by-Barry-N-Malzberg.pdf
    • http://loaminoo.linkpc.net/4093097098096/Gomorrah-by-Roberto-Saviano.pdf
    • http://loaminoo.linkpc.net/9093098092096/The-Gomorrah-Principle-by-Rick-DeStefanis.pdf
    • http://loaminoo.linkpc.net/4092091098097097/Entrepreneurship-The-Online-Money-Factory---Online-Business-Home-Business-amp-Business-Startup-by-Brian-Windley.pdf
    • http://loaminoo.linkpc.net/1098099097090098/Republican-Gomorrah-Inside-the-Movement-that-Shattered-the-Party-by-Max-Blumenthal.pdf
    • http://loaminoo.linkpc.net/2098091097098093/Behind-the-Gates-of-Gomorrah-A-Year-with-the-Criminally-Insane-by-Stephen-Seager.pdf
    • http://loaminoo.linkpc.net/1090091090094098092/The-effectiveness-of-a-government-high-technology-small-business-program-within-a-small-business-incubator-A-case-study-in-government-university-and-business-collaboration-by-Anila-Nandkishore-Strahan.pdf
    • http://loaminoo.linkpc.net/2099092097091092/120-Days-of-Sodom-by-Marquis-de-Sade.pdf
    • http://loaminoo.linkpc.net/3096096098090097/Sodom-Had-No-Bible-by-Leonard-Ravenhill.pdf
    • http://loaminoo.linkpc.net/7097098097090097/The-Protocols-of-the-Elders-of-Sodom-and-Other-Essays-by-Tariq-Ali.pdf
    • http://loaminoo.linkpc.net/1097090091094097/Sodom-and-the-Phoenix-Virtual-Seduction-2-by-Ann-Mayburn.pdf
    • http://loaminoo.linkpc.net/2098091093095096/Sodom-and-Detroit-Virtual-Seduction-1-by-Ann-Mayburn.pdf
    • http://loaminoo.linkpc.net/7097091097091091/Sodom-A-Nation-On-Its-Knees-The-Search-for-the-Righteous-1-by-Pam-Funke.pdf
    • http://loaminoo.linkpc.net/4095094091094097/Vampire-Lesbians-of-Sodom-and-Sleeping-Beauty-or-Coma-by-Charles-Busch.pdf
    • http://loaminoo.linkpc.net/9096094096098096/Die-Priesterin-von-Sodom-Eine-erotische-BDSM-Fantasie-by-Seth-Daniels.pdf
    • http://loaminoo.linkpc.net/3094099091091090/Live-Right-and-Find-Happiness-Although-Beer-is-Much-Faster-Life-Lessons-and-Other-Ravings-from-Dave-Barry-by-Dave-Barry.pdf