Malicious PDF — malware analysis report

Static analysis result for SHA-256 41252d0ec162b72a…

MALICIOUS

PDF

17.2 KB Created: 2019-05-02 07:03:53 +01:00 Authoring application: mPDF 5.7
MD5: afe1d52d23a1e0a28c8c330cd6c32235 SHA-1: f814093dfed0ba2e3f5e5e7ab5534bd1b023c45c SHA-256: 41252d0ec162b72a4a88a68a96ca23a1ca65941059288c9f4b3f5e9697c3171f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs pointing to external PDF files, characteristic of a link farm. The primary heuristic indicates this is a PDF SEO link farm, suggesting the document's purpose is to drive traffic to these external resources, likely for malicious purposes such as hosting further malware or phishing content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8099093094099091/Yearning-for-Normal-My-Son-s-Life-with-Deletion-22q-11-by-Susan-Ellison-Busch.pdf
    • http://loaminoo.linkpc.net/4096097095095098/Yearning-Absolution-Yearning-Series-2-by-Rachael-Orman.pdf
    • http://loaminoo.linkpc.net/2096091097094/The-Essential-Ellison-A-50-Year-Retrospective-by-Harlan-Ellison.pdf
    • http://loaminoo.linkpc.net/9098099090093093/The-Harlan-Ellison-Hornbook-Harlan-Ellison-s-Movie-Edgeworks-3-by-Harlan-Ellison.pdf
    • http://loaminoo.linkpc.net/3096092094096093/A-Normal-Family-Everyday-adventures-with-our-autistic-son-by-Henry-Normal.pdf
    • http://loaminoo.linkpc.net/1098099098095092/The-Normal-Christian-Life-by-Watchman-Nee.pdf
    • http://loaminoo.linkpc.net/2094096092096/The-Essential-Ellison-by-Harlan-Ellison.pdf
    • http://loaminoo.linkpc.net/8099093095097099/David-Busch-s-Nikon-D3100-Guide-to-Digital-Slr-Photography-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/8099093095099092/David-Busch-s-Quick-Snap-Guide-to-Using-Digital-SLR-Lenses-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/6099093090095091/David-Busch-s-Sony-Alpha-Slt-A65-Guide-to-Digital-Photography-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/8099093094099097/David-Busch-s-Nikon-D3200-Guide-to-Digital-Slr-Photography-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/6099093090094099/David-Busch-s-Sony-Alpha-Nex-5N-Guide-to-Digital-Photography-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/8099093095098093/David-Busch-s-Digital-Infrared-Pro-Secrets-by-David-D-Busch.pdf
    • http://loaminoo.linkpc.net/6097094093090098/Inventing-Disease-and-Pushing-Pills-Pharmaceutical-Companies-and-the-Medicalisation-of-Normal-Life-by-J-Blech.pdf
    • http://loaminoo.linkpc.net/9098099096091/Yearning-for-the-Living-God-Reflections-from-the-Life-of-F-Enzio-Busche-by-F-Enzio-Busche.pdf
    • http://loaminoo.linkpc.net/9098098099095095/Troublemakers-Stories-by-Harlan-Ellison-by-Harlan-Ellison.pdf
    • http://loaminoo.linkpc.net/4092091091094093/Melissa-Explains-It-All-Tales-from-My-Abnormally-Normal-Life-by-Melissa-Joan-Hart.pdf
    • http://loaminoo.linkpc.net/1097099095091091/Your-Perfect-Life---How-to-Use-the-Law-of-Attraction-to-Get-the-Life-You-Deserve-by-Susan-Edwards.pdf
    • http://loaminoo.linkpc.net/3095092099091090/The-Yearning-by-A-J-Rose.pdf
    • http://loaminoo.linkpc.net/4094093097098/Faking-Normal-Faking-Normal-1-by-Courtney-C-Stevens.pdf
    • http://loaminoo.linkpc.net/8099093094099097/David-Busch-s-Nikon-D3200-Guide-to-Digi