Malicious PDF — malware analysis report

Static analysis result for SHA-256 47f478a0721a7f85…

MALICIOUS

PDF

23.3 KB Created: 2019-05-02 01:36:56 +01:00 Authoring application: mPDF 5.7
MD5: a48e9658d3a9beb56d57590e80d0d3b1 SHA-1: 49fb568435561088015ab59275ec0ad6d10267af SHA-256: 47f478a0721a7f8500910b6f60f0c7489b21ac9af749fccf82d6315efeefe50a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099090092097093/Security-Breach-Rogue-Security-and-Investigation-1-by-Evan-Grace.pdf
    • http://loaminoo.linkpc.net/1090091093096094/Lead-Security-Rogue-Security-and-Investigation-3-by-Evan-Grace.pdf
    • http://loaminoo.linkpc.net/6096091097090095/Implementing-Cisco-IOS-Network-Security-IINS-CCNA-Security-exam-640-553-Authorized-Self-Study-Guide-by-Catherine-Paquet.pdf
    • http://loaminoo.linkpc.net/9096091097099094/Der-IT-Security-Manager-Aktuelles-Praxiswissen-f-r-IT-Security-Manager-und-IT-Sicherheitsbeauftragte-in-Unternehmen-und-Beh-rden-by-Heinrich-Kersten.pdf
    • http://loaminoo.linkpc.net/9096091097099093/Der-It-Security-Manager-Aktuelles-Praxiswissen-Fur-It-Security-Manager-Und-It-Sicherheitsbeauftragte-in-Unternehmen-Und-Behorden-by-Heinrich-Kersten.pdf
    • http://loaminoo.linkpc.net/9096091098096091/Der-IT-Security-Manager-Aktuelles-Praxiswissen-f-r-IT-Security-Manager-und-IT-Sicherheitsbeauftragte-in-Unternehmen-und-Beh-rden-by-Kersten.pdf
    • http://loaminoo.linkpc.net/6095096093094094/Institute-of-Pacific-Relations-Vol-7-Hearings-Before-the-Subcommittee-to-Investigate-the-Administration-of-the-Internal-Security-ACT-and-Other-Internal-Security-Laws-of-the-Committee-on-the-Judiciary-United-States-Senate-Eighty-Second-Congress-Janua-by-U-S-Senate.pdf
    • http://loaminoo.linkpc.net/9098099092094099/Dragon-Security-Boxed-Set-Dragon-Security-1-6-by-Glenna-Sinclair.pdf
    • http://loaminoo.linkpc.net/1090097094092099091/Old-Assumptions-New-Realities-Ensuring-Economic-Security-for-Working-Families-in-the-21st-Century-Ensuring-Economic-Security-for-Working-Families-in-the-21st-Century-by-Robert-D-Plotnick.pdf
    • http://loaminoo.linkpc.net/8096090095095097/Joomla-Web-Security-by-Tom-Canavan.pdf
    • http://loaminoo.linkpc.net/4094097098097090/Security-by-Mike-Shade.pdf
    • http://loaminoo.linkpc.net/6098096095098095/Apache-Security-by-Ivan-Ristic.pdf
    • http://loaminoo.linkpc.net/2098095099098094/Saying-I-Do-Quinn-Security-3-by-Cameron-Dane.pdf
    • http://loaminoo.linkpc.net/4093098091095097/Your-Safety-And-Security-In-Rio-de-Janeiro-by-F-Otieno.pdf
    • http://loaminoo.linkpc.net/4099095092092094/Never-Say-Never-Sniper-1-Security-2-by-Nicole-Edwards.pdf
    • http://loaminoo.linkpc.net/6090095090092092/Desperate-Cunningham-Security-3-by-A-K-Evans.pdf
    • http://loaminoo.linkpc.net/2091094094096094/The-End-CageVec-Security-3-by-Tara-Sivec.pdf
    • http://loaminoo.linkpc.net/4093098091093091/Your-Safety-and-Security-in-Rio-de-Janeiro-by-F-Otieno.pdf
    • http://loaminoo.linkpc.net/7097099090090091/Security-Warrior-by-Cyrus-Peikari.pdf
    • http://loaminoo.linkpc.net/1090091096099098091/Database-Security-by-Silvana-Casta-o.pdf
    • http://loaminoo.linkpc.net/9096091097099093/Der-It-Se