Malicious PDF — malware analysis report

Static analysis result for SHA-256 16cc217bb8a21f27…

MALICIOUS

PDF

16.4 KB Created: 2019-05-01 17:34:16 +01:00 Authoring application: mPDF 5.7
MD5: f5b9786f287ce1e1e63c79fc6beb9b18 SHA-1: c77f7ed3cf8502608547319deeb3bf46021ffe58 SHA-256: 16cc217bb8a21f27b2bea279ef28cf46870bef07a1467b0e90ea21fdf77e04c9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' indicate a likely attempt to manipulate search engine results or distribute content through a large number of redirects. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097090097092094/Rosie-s-Resolutions-by-Maggie-Ryan.pdf
    • http://loaminoo.linkpc.net/8094094090096092/Audition-for-Murder-Maggie-Ryan-1967-Maggie-Ryan-and-Nick-O-Connor-1-by-P-M-Carlson.pdf
    • http://loaminoo.linkpc.net/2097092097097/Murder-Is-Academic-Maggie-Ryan-1968-Maggie-Ryan-and-Nick-O-Connor-2-by-P-M-Carlson.pdf
    • http://loaminoo.linkpc.net/9095096096096094/Vintage-Values-Corbin-s-Bend-Season-Four-5-by-Maggie-Ryan.pdf
    • http://loaminoo.linkpc.net/1091097094098093098/Everything-Rosie-The-Untimate-Guide-for-Rosie-O-Donnell-Fans-by-Patrick-Spreng.pdf
    • http://loaminoo.linkpc.net/1091097094099097097/Everything-Rosie-The-Ultimate-Guide-for-Rosie-O-Donnell-Fans-by-Patrick-Spreng.pdf
    • http://loaminoo.linkpc.net/2099094090097091/Rosie-s-Gift-Rosie-McGrath-3-by-Ann-Carroll.pdf
    • http://loaminoo.linkpc.net/2095098092093098/Rosie-s-Quest-Rosie-McGrath-1-by-Ann-Carroll.pdf
    • http://loaminoo.linkpc.net/2096090094093097/Christmas-at-Rosie-Hopkins-Sweetshop-Rosie-Hopkins-Sweet-Shop-2-by-Jenny-Colgan.pdf
    • http://loaminoo.linkpc.net/3090091091098090/Resolutions-Honor-Guard-Series-by-Teri-Riggs.pdf
    • http://loaminoo.linkpc.net/3097095099099097/United-Nations-Resolutions-On-Palestine-And-The-Arab-Israeli-Conflict-by-George-J-Tomeh.pdf
    • http://loaminoo.linkpc.net/2091099090099095/Maggie-Goes-to-Hollywood-Maggie-MacKay-Magical-Tracker-6-by-Kate-Danley.pdf
    • http://loaminoo.linkpc.net/2091099090098090/Maggie-Get-Your-Gun-Maggie-MacKay-Magical-Tracker-2-by-Kate-Danley.pdf
    • http://loaminoo.linkpc.net/2090096098096095/Find-Me-Maggie-The-Misadventures-of-Maggie-Mae-3-by-Beth-Yarnall.pdf
    • http://loaminoo.linkpc.net/2090096095094092/You-re-Mine-Maggie-The-Misadventures-of-Maggie-Mae-2-by-Beth-Yarnall.pdf
    • http://loaminoo.linkpc.net/2099095093099098/Tip-It-The-World-According-to-Maggie-by-Maggie-Griffin.pdf
    • http://loaminoo.linkpc.net/8093098090094094/The-Devaney-Brothers-Ryan-and-Sean-Ryan-s-Place-Sean-s-Reckoning-by-Sherryl-Woods.pdf
    • http://loaminoo.linkpc.net/2092092091091092/Patriot-Games-Jack-Ryan-1-Jack-Ryan-Universe-2-by-Tom-Clancy.pdf
    • http://loaminoo.linkpc.net/2090090096091092/Can-t-Get-Enough-by-Rosie-Allen.pdf
    • http://loaminoo.linkpc.net/6099096095097094/Rosie-and-the-Rustlers-by-Roy-Gerrard.pdf