Malicious PDF — malware analysis report

Static analysis result for SHA-256 1fe66ce41f7621ff…

MALICIOUS

PDF

19.4 KB Created: 2019-05-02 17:57:51 +01:00 Authoring application: mPDF 5.7
MD5: 1c054ee16b0552f90bbbd1002ec2cb4c SHA-1: ee5625743e00f363f1efb58f83b90326bea32154 SHA-256: 1fe66ce41f7621ff21491310f03188269817a9099d9c9a7a2cb75dd7eae59b49
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic identified a mass external link farm. The URLs themselves, while many are marked benign, are hosted on a suspicious domain, suggesting a potential distribution or lure mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2091090095092098/An-Irish-Country-Village-Irish-Country-2-by-Patrick-Taylor.pdf
    • http://loaminoo.linkpc.net/2098098090098097/An-Irish-Country-Girl-Irish-Country-4-by-Patrick-Taylor.pdf
    • http://loaminoo.linkpc.net/3094090096092096/Fingal-O-Reilly-Irish-Doctor-Irish-Country-8-by-Patrick-Taylor.pdf
    • http://loaminoo.linkpc.net/2093097096094091/An-Irish-Country-Doctor-by-Patrick-Taylor.pdf
    • http://loaminoo.linkpc.net/2098098090098094/A-Dublin-Student-Doctor-Irish-Country-6-by-Patrick-Taylor.pdf
    • http://loaminoo.linkpc.net/4096090097093098/Murder-at-an-Irish-Wedding-Irish-Village-Mystery-2-by-Carlene-O-39-Connor.pdf
    • http://loaminoo.linkpc.net/3098095090096095/An-Irish-Country-Childhood-Memories-of-a-Bygone-Age-by-Marrie-Walsh.pdf
    • http://loaminoo.linkpc.net/3098093095091098/The-Irish-Devil-Irish-Eyes-1-Irish-Eyes-Duo-1-by-Donna-Fletcher.pdf
    • http://loaminoo.linkpc.net/4093090097091095/Thicker-Than-Water-Coming-of-Age-Stories-by-Irish-amp-Irish-American-Writers-by-Gordon-Snell.pdf
    • http://loaminoo.linkpc.net/3092095091094095/Irish-Thoroughbred-Irish-Hearts-1-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/5095094093090091/The-Story-of-Ancient-Irish-Civilisation-by-Patrick-Weston-Joyce.pdf
    • http://loaminoo.linkpc.net/8092091093096094/Irish-Dance-Riverdance-the-Pirate-Queen-Irish-Stepdance-Ceilidh-Clare-Lancers-Set-Feis-Celtic-Tiger-Live-Garryowen-Sean-Nos-Dance-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/1099092096095096/Easter-Rising-An-Irish-American-Coming-Up-from-Under-by-Michael-Patrick-MacDonald.pdf
    • http://loaminoo.linkpc.net/3094094091094097/The-English-Country-House-From-the-Archives-of-Country-Life-by-Mary-Miers.pdf
    • http://loaminoo.linkpc.net/1096095091099092/The-Civil-War-of-1812-American-Citizens-British-Subjects-Irish-Rebels-amp-Indian-Allies-by-Alan-Taylor.pdf
    • http://loaminoo.linkpc.net/3094097095090093/A-Taste-Of-Country-Country-Love-2-by-Vicki-Green.pdf
    • http://loaminoo.linkpc.net/4099097099095095/The-Illustrated-History-of-Country-Music-by-Patrick-Carr.pdf
    • http://loaminoo.linkpc.net/3099091099090093/Hill-Country-Rage-A-Joe-Robbins-Financial-Thriller-2-by-Patrick-Kelly.pdf
    • http://loaminoo.linkpc.net/1090091093099092096/ANDORRA-Country-Studies-A-brief-comprehensive-study-of-Andorra-Country-Notes-by-Central-Intelligence-Agency.pdf
    • http://loaminoo.linkpc.net/8095099090096099/The-Death-of-the-West-How-Dying-Populations-and-Immigrant-Invasions-Imperil-Our-Country-and-Civilization-by-Patrick-J-Buchanan.pdf
    • http://loaminoo.linkpc.net/5095094093090091/The-Stor