Malicious PDF — malware analysis report

Static analysis result for SHA-256 4c3892ff0dcf21a5…

MALICIOUS

PDF

19.7 KB Created: 2019-04-30 04:16:17 +01:00 Authoring application: mPDF 5.7
MD5: f446ebe5a8d77e5903d24fc9e994ac5d SHA-1: 83dbaa97dc6212ff8816264729ae274be3b54fda SHA-256: 4c3892ff0dcf21a572ea229bee2d8ecc00b48356db561ef26e733b01fc58fa00
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM specifically identified this behavior, indicating a likely attempt to drive traffic to external sites. While the specific intent beyond link distribution is unclear, the sheer volume of links suggests a malicious purpose, possibly for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9099093096091090/A-Study-Guide-for-Nathaniel-Hawthorne-s-the-Birthmark-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/8095098099095099/A-Study-Guide-for-Moliere-s-Tartuffe-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/1091094097095096093/A-Study-Guide-for-Jonathan-Franzen-s-the-Corrections-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/8098096098092093/A-Study-Guide-for-Laurie-Halse-Anderson-s-Speak-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/7095093094094098/A-Study-Guide-for-Edwidge-Danticat-s-Caroline-s-Wedding-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/1091092097098098096/A-Study-Guide-for-Alice-Sebold-s-the-Lovely-Bones-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/6098097094098097/A-Study-Guide-for-Psychologists-and-Their-Theories-for-Students-Alfred-Binet-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/1091092094093090093/A-Study-Guide-for-Michael-Chabon-s-the-Amazing-Adventures-of-Kavalier-amp-Clay-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/6091097094099092/A-Study-Guide-for-Anna-Akhmatova-s-quot-Voronezh-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/6091097094096095/A-Study-Guide-for-Anna-Akhmatova-s-quot-Requiem-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/1091093097090095090/A-Study-Guide-for-Kazuo-Ishiguro-s-quot-the-Remains-of-the-Day-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/5092094092097091/A-Study-Guide-for-Guy-de-Maupassant-s-quot-Boule-de-Suif-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/7095093093099095/A-Study-Guide-for-Edwidge-Danticat-s-quot-ghosts-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/8095092095096098/A-Study-Guide-for-Anthony-Doerr-s-quot-the-Shell-Collector-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/7095096097090093/A-Study-Guide-for-Bernard-Dadie-s-quot-dry-Your-Tears-Africa-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/5098094096095096/A-Study-Guide-for-Yasunari-Kawabata-s-quot-grasshopper-and-the-Bell-Cricket-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/1091090095099099099/A-Study-Guide-for-Audrey-Niffenegger-s-quot-The-Time-Traveler-s-Wife-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/1090096091095099096/A-Study-Guide-for-Mark-Hollmann-Greg-Kotis-s-quot-Urinetown-quot-by-Cengage-Learning-Gale.pdf
    • http://loaminoo.linkpc.net/9099093097090098/Great-American-Short-Stories-vol-1-The-Birthmark-The-Threefold-Destiny-An-Old-Woman-s-Tale-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/1091096091098097098/Acronyms-Initialisms-amp-Abbreviations-by-Gale-Cengage-Learning.pdf
    • http://loaminoo.linkpc.net/6098097094098097/A-Study-Guide-for-Psychologists-and-Their-Theories-for-Students-Alfr