Malicious PDF — malware analysis report

Static analysis result for SHA-256 2ba4f3e0bafeca43…

MALICIOUS

PDF

20.8 KB Created: 2019-04-30 06:26:58 +01:00 Authoring application: mPDF 5.7
MD5: f64b930e594b8d7b465b175b0f9a465e SHA-1: e7d57e761062475f27c41f1c65aacf87d77e945b SHA-256: 2ba4f3e0bafeca4378f2ea56e4b42671ba5b970c3241a8ab8959c626e2dfb571
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern appears to be a link farm designed to direct users to external resources, potentially for SEO manipulation or to distribute malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5094091091097091/BABYLONE-5-T01-LES-VOIX-PSY-by-John-Vernholt.pdf
    • http://loaminoo.linkpc.net/7097096093090098/Le-grand-livre-de-la-technique-vocale-Voix-parl-e-et-voix-chant-e---Principe-pour-respirer-techniques-pour-poser-sa-voix-conseils-pour-rythmer-son-discours-by-Herv-Pata.pdf
    • http://loaminoo.linkpc.net/5094091091093091/La-Princesse-de-Babylone-by-Louis-Moland.pdf
    • http://loaminoo.linkpc.net/5094091091097095/ACORN-6-DESPERADO-12-Baby-alone-in-Babylone-by-.pdf
    • http://loaminoo.linkpc.net/5094091091098098/Babylone-Chretienne-Geopolitique-De-L-eglise-De-Mesopotamie-Habiter-by-Joseph-Yacoub.pdf
    • http://loaminoo.linkpc.net/6090099091095091/VOIX-DE-LA-CONNAISSANCE-by-Miguel-Ruiz.pdf
    • http://loaminoo.linkpc.net/8092093090093095/Voix-int-rieures-by-Victor-Hugo.pdf
    • http://loaminoo.linkpc.net/6090099091096098/L-Ombre-De-MA-Voix-by-Patricia-Kaas.pdf
    • http://loaminoo.linkpc.net/5092099094099091/The-Human-Voice-A-Play-La-Voix-Humaine-by-Jean-Cocteau.pdf
    • http://loaminoo.linkpc.net/6090099091097090/Dismantling-Democracy-Stifling-debate-and-dissent-in-Canada-by-voices-voix.pdf
    • http://loaminoo.linkpc.net/8092092099094094/La-voix-de-la-connaissance-Un-guide-pratique-vers-la-paix-int-rieure-by-Miguel-Ruiz.pdf
    • http://loaminoo.linkpc.net/7090091099093097/Ocean-Of-Sound-Musiques-Ambiantes-Mondes-Imaginaires-Et-Autres-Voix-De-L-ther-by-David-Toop.pdf
    • http://loaminoo.linkpc.net/6094095096090092/Un-Texte-Une-Voix-L-int-grale-de-la-saison-2013-avec-les-interviews-et-les-extraits-en-un-seul-epub-by-Regine-Detambel.pdf
    • http://loaminoo.linkpc.net/8099090093092091/Chemistry-and-Chemical-Reactivity-John-C-Kotz-Paul-M-Treichel-John-R-Townsend-by-John-C-Kotz.pdf
    • http://loaminoo.linkpc.net/3096098092096098/Articles-on-Outlander-Including-Diana-Gabaldon-Lord-John-and-the-Private-Matter-Lord-John-and-the-Brotherhood-of-the-Blade-Lord-John-and-the-Scot-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/5097091098092091/Forty-Dreams-Of-St-John-Bosco-From-St-John-Bosco-s-Biographical-Memoirs-by-John-Bosco.pdf
    • http://loaminoo.linkpc.net/1097091098095/Goombata-The-Improbable-Rise-and-Fall-of-John-Gotti-and-His-Gang-by-John-Cummings.pdf
    • http://loaminoo.linkpc.net/6092099098095092/Seeking-John-Campbell-Finding-pioneers-and-patriots-in-the-pampas-by-John-Daffurn.pdf
    • http://loaminoo.linkpc.net/9091095093095/Before-John-Was-a-Jazz-Giant-A-Song-of-John-Coltrane-by-Carole-Boston-Weatherford.pdf
    • http://loaminoo.linkpc.net/1091091092094090094/Tod-im-Kilt-John-Mackenzies-zweiter-Fall-John-Mackenzie-2-by-Emma-Goodwyn.pdf
    • http://loaminoo.linkpc.net/609009909109709