Malicious PDF — malware analysis report

Static analysis result for SHA-256 3b9f11176aeaba68…

MALICIOUS

PDF

15.2 KB Created: 2019-04-30 02:16:35 +01:00 Authoring application: mPDF 5.7
MD5: 02ce98299447720d0431b07f72ab1e54 SHA-1: 3c55eaf3ba2e55f3c8ee4f855a7027e88b6cb2d4 SHA-256: 3b9f11176aeaba687a3dea1efb1be2088635311663a4615f1fc5832b4200c588
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were individually classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to serve as a landing page for further malicious activity. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099097099097099/Blues-Chaos-The-Music-Writing-of-Robert-Palmer-by-Robert-Palmer.pdf
    • http://loaminoo.linkpc.net/2090091092094095/The-County-Courts-of-Medieval-England-1150-1350-by-Robert-C-Palmer.pdf
    • http://loaminoo.linkpc.net/1091091091093095092/Memphis-Rent-Party-The-Blues-Rock-amp-Soul-in-Music-s-Hometown-by-Robert-Gordon.pdf
    • http://loaminoo.linkpc.net/9094096091090094/Teaching-Through-the-ARTS-WRITING-Volume-1-by-Mary-Palmer-and-Susan-Merrill-Rosoff.pdf
    • http://loaminoo.linkpc.net/2097091094099099/Books-Movies-Rhythm-Blues-Twenty-Years-of-Writing-About-Film-Music-and-Books-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/2097095093091090/Elements-of-the-Writing-Craft-Robert-Olmstead-by-Robert-Olmstead.pdf
    • http://loaminoo.linkpc.net/2090099091097090/Red-Planet-Blues-by-Robert-J-Sawyer.pdf
    • http://loaminoo.linkpc.net/5092093095094091/Le-Seigneur-du-Chaos-La-Roue-du-temps-T6-by-Robert-Jordan.pdf
    • http://loaminoo.linkpc.net/2097096095090094/The-Now-Awards-The-Best-Innovative-Writing-by-Robert-Archambeau.pdf
    • http://loaminoo.linkpc.net/1091094097090093/Gulf-Music-Poems-by-Robert-Pinsky.pdf
    • http://loaminoo.linkpc.net/8091099093094092/The-Birth-of-Writing-The-Emergence-of-Man-Series-by-Robert-Claiborne.pdf
    • http://loaminoo.linkpc.net/9090098096093090/The-Sense-of-Music-Semiotic-Essays-by-Robert-Hatten.pdf
    • http://loaminoo.linkpc.net/1092096096090090/Birthright-by-R-J-Palmer.pdf
    • http://loaminoo.linkpc.net/4092091096096099/Rock-Music-in-American-Culture-The-Sounds-of-Revolution-by-Robert-G-Pielke.pdf
    • http://loaminoo.linkpc.net/3093097099094092/Seeing-Me-Naked-by-Liza-Palmer.pdf
    • http://loaminoo.linkpc.net/5090092091093098/Magnolia-by-Diana-Palmer.pdf
    • http://loaminoo.linkpc.net/3094094096095093/Noelle-by-Diana-Palmer.pdf
    • http://loaminoo.linkpc.net/3094098095091098/Lawless-by-Diana-Palmer.pdf
    • http://loaminoo.linkpc.net/3092099099092092/Threshold-by-David-R-Palmer.pdf
    • http://loaminoo.linkpc.net/1091091097099096097/The-Reformation-by-Lee-Palmer-Wandel.pdf