Malicious PDF — malware analysis report

Static analysis result for SHA-256 475b1dd5e6169890…

MALICIOUS

PDF

24.0 KB Created: 2019-05-01 17:30:27 +01:00 Authoring application: mPDF 5.7
MD5: b40ad4fd61315a1542622ac1156f5755 SHA-1: 13340d41a33b0781478b9f770fee00731c3d7f31 SHA-256: 475b1dd5e6169890ea571ce2653118fd1b2d6582f0e00a0b70f6dfc82dd57d2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted were classified as benign, the sheer volume and structure suggest a malicious intent, likely for SEO poisoning or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicates maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093096097090099/The-Ultimate-Unauthorized-Eragon-Guide-The-Hidden-Facts-Behind-the-World-of-Alagaesia-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/1090093091091091092/The-Divergent-Companion-The-Unauthorized-Guide-to-the-Series-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/6093092093092090/The-Mortal-Instruments-Companion-City-of-Bones-Shadowhunters-and-the-Sight-The-Unauthorized-Guide-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/4095095096095/Eragon-s-Guide-to-Alaga-sia-by-Christopher-Paolini.pdf
    • http://loaminoo.linkpc.net/2099091094094095/The-Science-of-Superheroes-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/3091099098090099/Exploring-Philip-Pullman-s-His-Dark-Materials-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/1091092096094091097/World-of-Warcraft-Ultimate-Visual-Guide-by-Alastair-Dougall.pdf
    • http://loaminoo.linkpc.net/4090094090/Atlas-Obscura-An-Explorer-s-Guide-to-the-World-s-Hidden-Wonders-by-Joshua-Foer.pdf
    • http://loaminoo.linkpc.net/5093090090091090/Das-Erbe-der-Macht-E-Book-plus-Eragon-4-Eragon---Die-Einzelb-nde-by-Christopher-Paolini.pdf
    • http://loaminoo.linkpc.net/1091093096098090094/Eragon-108-Success-Secrets---108-Most-Asked-Questions-on-Eragon---What-You-Need-to-Know-by-Albert-Bridges.pdf
    • http://loaminoo.linkpc.net/6097090095097099/The-Ultimate-Ramadan-Holiday-Survival-Guide-for-Understanding-Ramadan-Rules-and-Ramadan-Fasting-Learn-The-Ramadan-Origin-and-Ramadan-Facts-Ramadan-Rules-Ramadan-Holiday-Ramadan-Festival-Book-1-by-Jenny-Husk.pdf
    • http://loaminoo.linkpc.net/3098096093099091/The-Hidden-Message-Adventures-of-the-Northwoods-2-by-Lois-Walfrid-Johnson.pdf
    • http://loaminoo.linkpc.net/3090098092099099/BH-Ultimate-Cookie-Book-More-than-500-Tempting-Treats-Plus-Secrets-for-Baking-Better-Cookies-by-Lois-White.pdf
    • http://loaminoo.linkpc.net/1091093096098094099/Eragon-Inheritance-Book-One-by-Christopher-Paolini-l-Summary-amp-Study-Guide-by-BookRags.pdf
    • http://loaminoo.linkpc.net/8095096099099099/Male-Multiple-Orgasm-The-Ultimate-Guide-on-Becoming-a-Multi-Orgasmic-Man-Gain-Ultimate-Control---Get-More-Pleasure---Give-More-Pleasure-by-B-Foyer.pdf
    • http://loaminoo.linkpc.net/1099095098093092/Ultimate-Teen-Book-Guide-Ultimate-Book-Guides-by-Leonie-Flynn.pdf
    • http://loaminoo.linkpc.net/1091096096094092091/99-Facts-about-Farts-The-Ultimate-Fun-Fact-Book-Fun-Fact-Books-by-J-N-Storm.pdf
    • http://loaminoo.linkpc.net/1091098094097096090/The-Vodka-1000-The-Ultimate-Collection-of-Vodka-Cocktails-Recipes-Facts-and-Resources-by-Ray-Foley.pdf
    • http://loaminoo.linkpc.net/2095095098095095/The-Hidden-Face-of-God-Science-Reveals-the-Ultimate-Truth-by-Gerald-Schroeder.pdf
    • http://loaminoo.linkpc.net/5097099091097093/Ultimate-Handbook-Guide-to-Bucharest-Romania-Travel-Guide-by-Hye-Ducharme.pdf