Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f1cf1a3cd1ec19f…

MALICIOUS

PDF

21.3 KB Created: 2019-05-07 03:30:55 +01:00 Authoring application: mPDF 5.7
MD5: d18ebb38416bb22526f478912005b579 SHA-1: c3cfde74729818328bb306a0c01d7ccac3f6f09f SHA-256: 3f1cf1a3cd1ec19f6a8c204ce00cc175e82381d1457617b211b96b208a959d1e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: User Execution

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a malicious intent to distribute content or manipulate search engine results. While many of these URLs are marked as confirmed benign, the sheer volume and the ML classifier's high confidence score indicate a likely malicious purpose. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9099097098098090/Histories-of-Sexuality-Antiquity-to-Sexual-Revolution-by-Stephen-Garton.pdf
    • http://loaminoo.linkpc.net/1091093091095096/The-Polish-Revolution-Solidarity-by-Timothy-Garton-Ash.pdf
    • http://loaminoo.linkpc.net/2095095098097098/Sexual-Meanings-The-Cultural-Construction-Of-Gender-And-Sexuality-by-Sherry-B-Ortner.pdf
    • http://loaminoo.linkpc.net/3092092091093092/The-Survivor-s-Guide-to-Sex-How-to-Create-Your-Own-Empowered-Sexuality-After-Childhood-Sexual-Abuse-by-Staci-K-Haines.pdf
    • http://loaminoo.linkpc.net/1091094093098095093/Moral-Revolution-The-Naked-Truth-About-Sexual-Purity-by-Kris-Vallotton.pdf
    • http://loaminoo.linkpc.net/7090093090094099/Sexing-the-Millenium-Political-History-of-the-Sexual-Revolution-by-Linda-Grant.pdf
    • http://loaminoo.linkpc.net/9097095095099091/Sex-in-Crisis-The-New-Sexual-Revolution-and-the-Future-of-American-Politics-by-Dagmar-Herzog.pdf
    • http://loaminoo.linkpc.net/1093098095092099/A-Tragic-Grace-The-Catholic-Church-and-Child-Sexual-Abuse-by-Stephen-J-Rossetti.pdf
    • http://loaminoo.linkpc.net/2097099095091099/The-French-Revolution-and-What-Went-Wrong-by-Stephen-Clarke.pdf
    • http://loaminoo.linkpc.net/7097093093095095/Punk-The-Definitive-Record-of-a-Revolution-by-Stephen-Colegrave.pdf
    • http://loaminoo.linkpc.net/7092096093093092/The-Sexual-Teachings-of-the-Jade-Dragon-Taoist-Methods-for-Male-Sexual-Revitalization-by-Hsi-Lai.pdf
    • http://loaminoo.linkpc.net/3095094099093091/The-Battle-of-St-Louis-The-Attack-on-Cahokia-and-the-American-Revolution-in-the-West-by-Stephen-L-Kling-Jr-.pdf
    • http://loaminoo.linkpc.net/1091092099098094094/Rush-Revolution-Madness-and-the-Visionary-Doctor-Who-Became-a-Founding-Father-by-Stephen-Fried.pdf
    • http://loaminoo.linkpc.net/1093095094096094/Erotic-Marriage-Break-Free-from-the-Negative-Sexual-Script-and-Improve-the-Sexual-and-Emotional-Quality-of-Your-Relationship-by-Frederick-D-Mondin.pdf
    • http://loaminoo.linkpc.net/8091098098093096/Kama-Sutra-Sexual-Positions-For-Him-And-For-Her-Sexual-Positions-For-Her-And-For-Him-by-Anne-Hooper.pdf
    • http://loaminoo.linkpc.net/9099097098096095/Pieces-of-Hate-by-Ray-Garton.pdf
    • http://loaminoo.linkpc.net/9099097099094092/Slivers-of-Bone-by-Ray-Garton.pdf
    • http://loaminoo.linkpc.net/9099097099095093/Invaders-From-Mars-by-Ray-Garton.pdf
    • http://loaminoo.linkpc.net/7098099094097094/Noodle-amp-Lou-by-Liz-Garton-Scanlon.pdf
    • http://loaminoo.linkpc.net/9099097098091096/Serpent-Girl-by-Ray-Garton.pdf