Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e731e113e9acb50…

MALICIOUS

PDF

15.4 KB Created: 2019-04-30 18:22:20 +01:00 Authoring application: mPDF 5.7
MD5: 9e5ccca4a04e19132b95034bbb105f6f SHA-1: 3f6ddcab5f66f7f89a19736518cab8675ba5d71b SHA-256: 1e731e113e9acb50b2923d9e4df70efd750d83131266aa86ed14c8dbe7e6bac1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, identified by the 'PDF_SEO_LINK_FARM' heuristic. The ML classifier also flagged this document as malicious. The embedded URLs, while marked as confirmed benign in this specific report, are part of a link farm designed to direct users to potentially malicious content, likely a form of SEO poisoning or a lure for further malicious downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6097094093094099/Those-Ragged-Bloody-Heroes-From-The-Kokoda-Trail-To-Gona-Beach-1942-by-Peter-Brune.pdf
    • http://loaminoo.linkpc.net/6097094094092096/Ralph-Honner-Kokoda-Hero-by-Peter-Brune.pdf
    • http://loaminoo.linkpc.net/1099091091094090/Kokoda-by-Peter-FitzSimons.pdf
    • http://loaminoo.linkpc.net/1090090098092090091/Storm-over-Kokoda-by-Peter-Ewer.pdf
    • http://loaminoo.linkpc.net/1099091097099099/A-Bastard-of-a-Place-The-Australians-in-Papua-by-Peter-Brune.pdf
    • http://loaminoo.linkpc.net/4097094090092095/The-Bloody-Bozeman-The-Perilous-Trail-to-Montana-s-Gold-by-Dorothy-M-Johnson.pdf
    • http://loaminoo.linkpc.net/1095094095099092/Ex-Heroes-Ex-Heroes-1-by-Peter-Clines.pdf
    • http://loaminoo.linkpc.net/2098095090093090/Life-and-Death-in-the-Andes-On-the-Trail-of-Bandits-Heroes-and-Revolutionaries-by-Kim-MacQuarrie.pdf
    • http://loaminoo.linkpc.net/3097096091094095/Bloody-Bonsai-Elderhostel-1-by-Peter-E-Abresch.pdf
    • http://loaminoo.linkpc.net/1091094097097098091/The-Camel-Trail-by-Peter-J-Merrigan.pdf
    • http://loaminoo.linkpc.net/9092093091095098/Bicycle-On-The-Beach-by-Peter-Viertel.pdf
    • http://loaminoo.linkpc.net/3092095094092096/Kate-Winfield-on-the-Oregon-Trail-by-Peter-Marshall.pdf
    • http://loaminoo.linkpc.net/1093092097092095/Ex-Communication-Ex-Heroes-3-by-Peter-Clines.pdf
    • http://loaminoo.linkpc.net/2093098096096091/Ex-Patriots-Ex-Heroes-2-by-Peter-Clines.pdf
    • http://loaminoo.linkpc.net/1093091090090097/Ex-Isle-Ex-Heroes-5-by-Peter-Clines.pdf
    • http://loaminoo.linkpc.net/4098097094093/Last-of-the-Dixie-Heroes-by-Peter-Abrahams.pdf
    • http://loaminoo.linkpc.net/1093091096099090/Ex-Purgatory-Ex-Heroes-4-by-Peter-Clines.pdf
    • http://loaminoo.linkpc.net/6091095098097095/SAS-Stories-of-Heroes-IX-9-Soldier-Z-Delta-Zero-One-Papa-Zero-One-by-Peter-Corrigan.pdf
    • http://loaminoo.linkpc.net/3090098092095091/Batman-Detective-Comics-Volume-8-Blood-of-Heroes-by-Peter-J-Tomasi.pdf
    • http://loaminoo.linkpc.net/1098091097095/Trail-of-Hope-Story-of-the-Mormon-Trail-by-William-W-Slaughter.pdf