Malicious PDF — malware analysis report

Static analysis result for SHA-256 1fc1e37065b150eb…

MALICIOUS

PDF

16.4 KB Created: 2019-05-02 05:27:22 +01:00 Authoring application: mPDF 5.7
MD5: ef97fd94e82867b56e9ca59011b20a9b SHA-1: c6b0f73af2750c2dce955347ee5fe5a1d5013e74 SHA-256: 1fc1e37065b150eb360375642b86b8ade8bba860a0aac7c14000685da287fe6c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a link farming or content distribution scheme. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. While the document body is heavily obfuscated, the presence of numerous links to external PDF files indicates a likely attempt to direct users to potentially malicious or unwanted content, possibly for SEO manipulation or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2094095096097097/Clouds-Of-Glory-A-Childhood-in-Hoxton-by-Bryan-Magee.pdf
    • http://loaminoo.linkpc.net/9098095093090098/Karl-Popper-by-Bryan-Magee.pdf
    • http://loaminoo.linkpc.net/3099095094091098/The-Great-Philosophers-An-Introduction-to-Western-Philosophy-by-Bryan-Magee.pdf
    • http://loaminoo.linkpc.net/6090092094092092/Confessions-of-a-Philosopher-A-Personal-Journey-Through-Western-Philosophy-from-Plato-to-Popper-by-Bryan-Magee.pdf
    • http://loaminoo.linkpc.net/2092093093091099/Bad-Childhood---Good-Life-How-to-Blossom-and-Thrive-in-Spite-of-an-Unhappy-Childhood-by-Laura-Schlessinger.pdf
    • http://loaminoo.linkpc.net/4096096099096095/Unfaded-Glory-Home-to-Glory-2-by-Sara-Arden.pdf
    • http://loaminoo.linkpc.net/1097098091090094/Electrical-Forensics-by-Steven-Magee.pdf
    • http://loaminoo.linkpc.net/5090095091092094/One-of-the-Family-by-Catherine-Fowler-Magee.pdf
    • http://loaminoo.linkpc.net/9090094094094092/The-Hegel-Dictionary-by-Glenn-A-Magee.pdf
    • http://loaminoo.linkpc.net/2099091094095093/Blaze-of-Glory-Blaze-of-Glory-1-by-Sheryl-Nantus.pdf
    • http://loaminoo.linkpc.net/1091099095095098097/Pixie-Led---The-Fey-Catcher-s-Daughter-by-Micki-Magee.pdf
    • http://loaminoo.linkpc.net/2095095099090094/Richard-Wagner-and-the-Nibelungs-by-Elizabeth-Magee.pdf
    • http://loaminoo.linkpc.net/7092099099096093/Derive-See-5-Web-of-Hearts-and-Souls-14-by-Jamie-Magee.pdf
    • http://loaminoo.linkpc.net/5090097093098093/The-Treasure-of-Gwenlais-The-Rienfield-Chronicles-1-by-M-T-Magee.pdf
    • http://loaminoo.linkpc.net/3092099096094097/Paradise-Island-Heavenly-Journey-by-Jon-Magee.pdf
    • http://loaminoo.linkpc.net/1097098095092094/Witness-See-2-Web-of-Hearts-and-Souls-5-by-Jamie-Magee.pdf
    • http://loaminoo.linkpc.net/6090097094096/The-Lagunitas-Story-So-you-want-to-start-a-brewery-by-Tony-Magee.pdf
    • http://loaminoo.linkpc.net/1094098091092097/Blakeshire-Insight-9-Web-of-Hearts-and-Souls-13-by-Jamie-Magee.pdf
    • http://loaminoo.linkpc.net/2092090098092092/Vindicate-Insight-5-Web-of-Hearts-and-Souls-7-by-Jamie-Magee.pdf
    • http://loaminoo.linkpc.net/1096099094096096/Specky-Magee-amp-The-Season-Of-Champions-by-Felice-Arena.pdf