Malicious PDF — malware analysis report

Static analysis result for SHA-256 1fe4449c08f36650…

MALICIOUS

PDF

18.8 KB Created: 2019-04-30 17:34:35 +01:00 Authoring application: mPDF 5.7
MD5: bc98c28bc68afa78428ee8afc6851eee SHA-1: 4a72361721d0c317ca323be51b974e868a59fe0d SHA-256: 1fe4449c08f366505294349b07093c5ac832bb97b942e8f7f760df0d04c7147d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates that these links are likely generated to manipulate search engine results, potentially as a lure for users to download further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/9098095092096094/The-Canterbury-Tales---Original-and-Modernised-Text-by-Geoffrey-Chaucer---Delphi-Classics-Illustrated-Delphi-Parts-Edition-Geoffrey-Chaucer-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/3090090094095095/The-Squire-s-Tale-Chaucer-s-Canterbury-Tales-1921-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/1099090099095098/The-Canterbury-Tales-Nine-Tales-and-the-General-Prologue-Authoritative-Text-Sources-and-Backgrounds-Criticism-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/2090095092090092/The-Canterbury-Tales-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/1090091099096090096/The-Canterbury-Tales-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/4090097095095099/The-Canterbury-Tales-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/5094098094091099/The-Canterbury-Tales-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/3092090092099093/The-Canterbury-Tales-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/9092093099099099/The-Canterbury-Tales-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/1090092092091092099/The-Canterbury-Tales-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/8096093093095090/The-Canterbury-Tales-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/4091096094093095/The-Canterbury-Tales-The-First-Fragment-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/6098098097094090/The-Tales-of-Canterbury-Complete-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/6099095098090094/Jean-D-Angouleme-s-Copy-of-the-Canterbury-Tales-An-Annotated-Edition-of-Bibliotheque-Nationale-s-Fonds-Anglais-39-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/9091091095094093/The-Canterbury-Tales-100-Greatest-Books-of-All-Time-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/1090090093091090093/The-Canterbury-Tales-De-Morgen-Bibliotheek-Boeken-van-Liefde-en-Lust-20-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/7093098098095091/Chaucer-Great-Books-of-the-Western-World-22-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/5093098099099097/Cuentos-de-Canterbury-Biblioteca-de-Grandes-Escritores-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/6099099092091097/Analogues-of-Chaucher-s-Canterbury-Pilgrimage-1903-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/4095098091091090/The-Riverside-Chaucer-by-Geoffrey-Chaucer.pdf