Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d8706656e855804…

MALICIOUS

PDF

20.6 KB Created: 2019-04-30 01:55:11 +01:00 Authoring application: mPDF 5.7
MD5: b8de89a5ea3c96fff1e5bedf1f2cf439 SHA-1: 5f56ea1ecd47a8add763661497f5d06cb09a158a SHA-256: 2d8706656e8558049af643775d48a74dd6907b06cbfe61b7f7719aa31cfb00e0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a link farm or phishing attempt. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. While the URLs themselves are currently marked as benign, the sheer volume and structure of the links indicate a malicious intent to direct users to external resources, likely for further exploitation or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090096096098094093/Critical-Thinking-in-Clinical-Research-Applied-Theory-and-Practice-Using-Case-Studies-by-Felipe-Fregni.pdf
    • http://loaminoo.linkpc.net/1091096096097095099/Handbook-of-Clinical-Neurology-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/1091096096099096093/Neurodystrophies-and-Neurolipidoses-Handbook-of-Clinical-Neurology-Series-by-Hugo-W-Moser.pdf
    • http://loaminoo.linkpc.net/2099090092090099/Surviving-Terminal-Cancer-Clinical-Trials-Drug-Cocktails-and-Other-Treatments-Your-Oncologist-Won-t-Tell-You-About-by-Ben-A-Williams.pdf
    • http://loaminoo.linkpc.net/9097096096094096/Bioartificial-Organs-Iii-Tissue-Sourcing-Immunoisolation-And-Clinical-Trials-Annals-Of-The-New-York-Academy-Of-Sciences-V-3-by-David-Hunkeler.pdf
    • http://loaminoo.linkpc.net/1091093099097096099/The-Mental-Status-Examination-in-Neurology-the-Mental-Status-Examination-in-Neurology-the-Mental-Status-Examination-in-Neurology-by-Richard-L-Strub.pdf
    • http://loaminoo.linkpc.net/2099094092095093/The-Angel-Trials-Dark-World-The-Angel-Trials-1-by-Michelle-Madow.pdf
    • http://loaminoo.linkpc.net/8090098096096095/Je-me-souviens-de-tous-vos-r-ves-by-Ren-Fr-gni.pdf
    • http://loaminoo.linkpc.net/8090098096097096/Archivi-Territori-Poteri-in-Area-Estense-by-Euride-Fregni.pdf
    • http://loaminoo.linkpc.net/6093091093096094/Hadnbook-of-Clin-Neurology-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/5096090091097091/The-Hospital-Neurology-Book-by-Arash-Salardini.pdf
    • http://loaminoo.linkpc.net/9095096098097093/Red-Blood-Cell-Substitutes-Basic-Principles-and-Clinical-Applications-Basic-Principles-and-Clinical-Applications-by-Alan-Rudolph.pdf
    • http://loaminoo.linkpc.net/8092090092090092/Penombre-et-Ischemie-Cerebrale-Current-problems-in-neurology-by-Niels-A-Lassen.pdf
    • http://loaminoo.linkpc.net/1091099095096095097/Columbus-by-Felipe-Fern-ndez-Armesto.pdf
    • http://loaminoo.linkpc.net/3092090092090098/SkateFate-by-Juan-Felipe-Herrera.pdf
    • http://loaminoo.linkpc.net/7098098093099090/The-Errant-Astrologers-by-Felipe-Ben-tez-Reyes.pdf
    • http://loaminoo.linkpc.net/2098098097098093/Locos-A-Comedy-of-Gestures-by-Felipe-Alfau.pdf
    • http://loaminoo.linkpc.net/1090096098095090097/Felipe-Calderon-by-Susan-Muaddi-Darraj.pdf
    • http://loaminoo.linkpc.net/3099095097094095/The-Love-Trials-1-The-Love-Trials-1-by-J-S-Cooper.pdf
    • http://loaminoo.linkpc.net/3097095094097099/The-Love-Trials-2-The-Love-Trials-2-by-J-S-Cooper.pdf
    • http://loaminoo.linkpc.net/9097096096094096/Bioartificial-Organs-Iii-Tissue-Sourcing-Immu