Malicious PDF — malware analysis report

Static analysis result for SHA-256 4fdf4f9910c2299c…

MALICIOUS

PDF

17.2 KB Created: 2019-04-30 04:01:54 +01:00 Authoring application: mPDF 5.7
MD5: 26ae8794b825793a97dbd13844bfa85c SHA-1: a3e3e05c7309d907d046f360d367e6e7c61380ae SHA-256: 4fdf4f9910c2299cfc94d775f9c6e24ec932082b903964d63ea61e84b59b9649
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified as a link farm. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a multitude of external URLs, likely for SEO poisoning or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5094096096098/Soul-Searching-by-J-M-Northup.pdf
    • http://loaminoo.linkpc.net/1096090091099090/Soul-Searching-Nodes-of-God-1-by-Keith-Caserta.pdf
    • http://loaminoo.linkpc.net/4091097092095094/Taking-the-Long-Way-Home-Soul-Searching-Across-America-by-Sonja-Millings.pdf
    • http://loaminoo.linkpc.net/1099093093099095/Soul-Searching-The-Religious-and-Spiritual-Lives-of-American-Teenagers-by-Christian-Smith.pdf
    • http://loaminoo.linkpc.net/4094097094091/Kill-Em-and-Leave-Searching-for-James-Brown-and-the-American-Soul-by-James-McBride.pdf
    • http://loaminoo.linkpc.net/1091093094097/Searching-for-Mine-Searching-For-4-5-1001-Dark-Nights-35-by-Jennifer-Probst.pdf
    • http://loaminoo.linkpc.net/5094099090094097/12-Years-a-Slave-Book-by-Solomon-Northup-Full-Twelve-Years-a-Slave-Original-Book-with-Annotated-Teaching-Lesson-Study-Guide-with-45-Essay-Questions-and-Answers-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/4091097093092/Searching-for-Perfect-Searching-For-2-by-Jennifer-Probst.pdf
    • http://loaminoo.linkpc.net/2091094091098096/Saving-Sam-by-J-M-Northup.pdf
    • http://loaminoo.linkpc.net/2099093094098097/A-Prisoner-Within-by-J-M-Northup.pdf
    • http://loaminoo.linkpc.net/3094095094092091/Soul-Whispers-II-Secret-Alchemy-of-the-Elements-in-Soul-Coaching-Soul-Whispers-2-by-Denise-Linn.pdf
    • http://loaminoo.linkpc.net/2094090093092095/12-Years-a-Slave-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/7095094096096096/12-Years-a-Slave-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/1090096094096092093/12-Years-A-Salve-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/4095093094099091/Twelve-Years-a-Slave-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/2096096097095097/Twelve-Years-a-Slave-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/5090095091094097/Twelve-Years-a-Slave-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/5093095095094091/12-years-a-slave---Le-livre-qui-a-inspir-le-film-de-Steve-McQueen-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/8090093090094098/Twelve-Years-a-Slave-Color-Illustrated-Formatted-for-E-Readers-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/5098099092092/Stolen-into-Slavery-The-True-Story-of-Solomon-Northup-Free-Black-Man-by-Judith-Bloom-Fradin.pdf
    • http://loaminoo.linkpc.net/5094099090094097/12-Years-a-Slave-Book-by-Solomon-Northup-Full-Twelve-Years-a-Slave-Original-Book-with-Annotated-Teaching-Lesson-Stud