Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d1c8788769d214e…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 05:18:04 +01:00 Authoring application: mPDF 5.7
MD5: d0d49dd36f2b8345581e5139e284acd8 SHA-1: b692fc293ee482397ab5ef820dcf190995b58a9f SHA-256: 3d1c8788769d214e7e97457847e1d50ce6a452a348f52b33cd810122f6da0576
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded URLs, identified as a link farm. While the specific content of the linked PDFs is benign, the heuristic 'PDF_SEO_LINK_FARM' indicates a pattern commonly used for SEO manipulation or to distribute malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9095095099092092/Brocabulary-The-New-Man-i-festo-of-Dude-Talk-by-Daniel-Maurer.pdf
    • http://loaminoo.linkpc.net/7093091097090096/The-Dude-De-Ching-by-The-Church-of-the-Latter-Day-Dude.pdf
    • http://loaminoo.linkpc.net/8098095091090090/Talk-Talk-A-Children-s-Book-Author-Speaks-to-Grown-Ups-by-E-L-Konigsburg.pdf
    • http://loaminoo.linkpc.net/1090097095098091095/Buddhists-Talk-About-Jesus-Christians-Talk-About-the-Buddha-by-Terry-Muck.pdf
    • http://loaminoo.linkpc.net/2096099093095098/What-We-Talk-about-When-We-Talk-about-the-Tube-The-District-Line-by-John-Lanchester.pdf
    • http://loaminoo.linkpc.net/2093094093092/What-We-Talk-About-When-We-Talk-About-Anne-Frank-by-Nathan-Englander.pdf
    • http://loaminoo.linkpc.net/4091090097095098/What-We-Talk-About-When-We-Talk-About-Love-Stories-by-Raymond-Carver.pdf
    • http://loaminoo.linkpc.net/8097095093096097/Jesus-Freaks-DC-Talk-and-The-Voice-of-the-Martyrs---Berichte-von-Menschen-die-bereit-waren-f-r-ihren-Glauben-bis-zum-u-ersten-zu-gehen-by-D-C-Talk.pdf
    • http://loaminoo.linkpc.net/3090099092092092/What-We-Talk-About-When-We-Talk-About-Love-by-Raymond-Carver.pdf
    • http://loaminoo.linkpc.net/3092094092096096/What-I-Talk-about-When-I-Talk-about-Running-by-Haruki-Murakami.pdf
    • http://loaminoo.linkpc.net/2097090098094091/I-Am-Positive-31-Positive-Self-Talk-Declarations-to-Speak-Faith-Over-Your-Life-Negative-Self-Talk-Book-2-by-Lynn-R-Davis.pdf
    • http://loaminoo.linkpc.net/4092099096095094/The-Dude-and-the-Zen-Master-by-Jeff-Bridges.pdf
    • http://loaminoo.linkpc.net/1094093096095093/Dude-Where-s-My-Country-by-Michael-Moore.pdf
    • http://loaminoo.linkpc.net/2099093098096/The-Wild-Colorado-by-Richard-Maurer.pdf
    • http://loaminoo.linkpc.net/9095095099091098/The-Wright-Sister-by-Richard-Maurer.pdf
    • http://loaminoo.linkpc.net/2091091094095099/A-Good-Dude-by-Keith-Walker.pdf
    • http://loaminoo.linkpc.net/1092093099093091/OCD-the-Dude-and-Me-by-Lauren-Roedy-Vaughn.pdf
    • http://loaminoo.linkpc.net/3093094098097095/The-Big-Con-The-Story-of-the-Confidence-Man-by-David-W-Maurer.pdf
    • http://loaminoo.linkpc.net/9095095099091096/The-Dark-Lady-s-Stone-by-Christie-Maurer.pdf
    • http://loaminoo.linkpc.net/2092097099095092/Dan-Gets-a-Minivan-Life-at-the-Intersection-of-Dude-and-Dad-by-Dan-Zevin.pdf
    • http://loaminoo.linkpc.net/8097095093096097/Jesus-Freaks-DC-Talk-and-The-Voice-of-the-Martyrs---Berichte-von-Menschen-die-bereit-waren-f-r-ihren-Glauben-bis-zum-u-ersten