Malicious PDF — malware analysis report

Static analysis result for SHA-256 1dff71445f3cd5eb…

MALICIOUS

PDF

16.5 KB Created: 2019-05-03 05:07:42 +01:00 Authoring application: mPDF 5.7
MD5: f99ebb50a5ea37f44f0ab59c08f877e9 SHA-1: 67064a264585cb8377e42dd3ffc13f3008c41ae4 SHA-256: 1dff71445f3cd5eb3b8d5fe653b96604bf42a81b6aa1bc48b64b2fea616dbe4e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5096097098/The-Pearl-Thief-Code-Name-Verity-0-5-by-Elizabeth-E-Wein.pdf
    • http://loaminoo.linkpc.net/4092093092091/Code-Name-Verity-Code-Name-Verity-1-by-Elizabeth-E-Wein.pdf
    • http://loaminoo.linkpc.net/3098097090093099/Code-Name-Verity-Code-Name-Verity-1-by-Elizabeth-E-Wein.pdf
    • http://loaminoo.linkpc.net/3090097092093/Code-Name-Verity-by-Elizabeth-E-Wein.pdf
    • http://loaminoo.linkpc.net/2092092096091091/Rose-Under-Fire-Code-Name-Verity-2-by-Elizabeth-E-Wein.pdf
    • http://loaminoo.linkpc.net/2092090099091091/Rose-Under-Fire-Code-Name-Verity-2-by-Elizabeth-E-Wein.pdf
    • http://loaminoo.linkpc.net/3091092092091/Rose-Under-Fire-by-Elizabeth-E-Wein.pdf
    • http://loaminoo.linkpc.net/2092099091098093/The-Empty-Kingdom-The-Lion-Hunters-5-by-Elizabeth-E-Wein.pdf
    • http://loaminoo.linkpc.net/4096096098099093/A-Coalition-of-Lions-The-Lion-Hunters-2-by-Elizabeth-E-Wein.pdf
    • http://loaminoo.linkpc.net/2097090097093096/The-Great-Pearl-Heist-London-s-Greatest-Thief-and-Scotland-Yard-s-Hunt-for-the-World-s-Most-Valuable-Necklace-by-Molly-Caldwell-Crosby.pdf
    • http://loaminoo.linkpc.net/2091096095093099/The-Davina-Code-by-Janet-Elizabeth-Henderson.pdf
    • http://loaminoo.linkpc.net/1092091095099092/Liar-s-Moon-Thief-Errant-2-by-Elizabeth-C-Bunce.pdf
    • http://loaminoo.linkpc.net/2095092096090/Thief-of-Shadows-Maiden-Lane-4-by-Elizabeth-Hoyt.pdf
    • http://loaminoo.linkpc.net/2092094096091095/Code-Name-Jack-Rabbit-The-Vampire-Guard-1-by-Elizabeth-Noble.pdf
    • http://loaminoo.linkpc.net/2095097090091094/The-Poems-Of-The-Pearl-Manuscript-Pearl-Cleanness-Patience-Sir-Gawain-And-The-Green-Knight-by-Unknown.pdf
    • http://loaminoo.linkpc.net/4097095093092094/A-Mighty-Heart-The-Brave-Life-and-Death-of-My-Husband-Danny-Pearl-by-Mariane-Pearl.pdf
    • http://loaminoo.linkpc.net/3090093093095/Defining-Pearl-a-precious-difference-by-Pearl-Matibe.pdf
    • http://loaminoo.linkpc.net/8092099092093/Mistress-of-the-Pearl-The-Pearl-Saga-3-by-Eric-Van-Lustbader.pdf
    • http://loaminoo.linkpc.net/1094095093095093/Shadows-of-Pearl-Pearl-2-by-Arianne-Richmonde.pdf
    • http://loaminoo.linkpc.net/3094092090093091/Pearl-and-Belle-Pearl-by-Arianne-Richmonde.pdf
    • http://loaminoo.linkpc.net/2091096095093099/The-Davi