Malicious PDF — malware analysis report

Static analysis result for SHA-256 5033a0d24bcb89a2…

MALICIOUS

PDF

17.7 KB Created: 2019-05-01 17:59:17 +01:00 Authoring application: mPDF 5.7
MD5: 1c0d3c9a029211dec4fcfe9690bf9c0c SHA-1: 9bac5d93a7365da1cdf0af606034a73365ba7e73 SHA-256: 5033a0d24bcb89a2939e8fa2c2c4ccba25aa89f28e79b3c4e7c4244860ba75a1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, such as http://loaminoo.linkpc.net/9099091096093/Compulsions-of-Silkworms-and-Bees-Poems-by-Julianna-Baggott.pdf, are likely part of a scheme to manipulate search engine rankings or redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9099091096093/Compulsions-of-Silkworms-and-Bees-Poems-by-Julianna-Baggott.pdf
    • http://loaminoo.linkpc.net/8093094092096090/Cendres-by-Julianna-Baggott.pdf
    • http://loaminoo.linkpc.net/3092094099091096/Fuse-Pure-2-by-Julianna-Baggott.pdf
    • http://loaminoo.linkpc.net/8091093095099/Burn-Pure-3-by-Julianna-Baggott.pdf
    • http://loaminoo.linkpc.net/2091092096091090/Pure-Pure-1-by-Julianna-Baggott.pdf
    • http://loaminoo.linkpc.net/4095090094091/Winter-Bees-amp-Other-Poems-of-the-Cold-by-Joyce-Sidman.pdf
    • http://loaminoo.linkpc.net/1098092093092095/Keeping-the-Bees-Why-All-Bees-Are-at-Risk-and-What-We-Can-Do-to-Save-Them-by-Laurence-Packer.pdf
    • http://loaminoo.linkpc.net/1090090093094090093/Pollination-with-Mason-Bees-A-Gardener-and-Naturalists-Guide-to-Managing-Mason-Bees-for-Fruit-Production-by-Margriet-Dogterom.pdf
    • http://loaminoo.linkpc.net/6098091094095/OBSESSED-The-Compulsions-and-Creations-of-Dr-Jeffrey-Schwartz-by-Steve-Volk.pdf
    • http://loaminoo.linkpc.net/4099094091091099/Battle-for-Control-A-Memoir-of-Anorexia-Exercise-Bulimia-and-Other-Compulsions-by-Doug-Erlandson.pdf
    • http://loaminoo.linkpc.net/4094098093097092/Atomic-The-First-War-of-Physics-and-the-Secret-History-of-the-Atom-Bomb-1939-49-by-Jim-Baggott.pdf
    • http://loaminoo.linkpc.net/3097096099099091/Just-Between-Friends-by-Julianna-Morris.pdf
    • http://loaminoo.linkpc.net/2094094095097090/His-Heart-s-Desire-by-Julianna-Douglas.pdf
    • http://loaminoo.linkpc.net/8097095098098095/Die-vierte-Braut-by-Julianna-Grohe.pdf
    • http://loaminoo.linkpc.net/7095099094092098/Undeclared-Burnham-College-2-by-Julianna-Keyes.pdf
    • http://loaminoo.linkpc.net/7098092096090/Rules-of-Murder-Drew-Farthering-Mystery-1-by-Julianna-Deering.pdf
    • http://loaminoo.linkpc.net/8098092096094/Death-by-the-Book-Drew-Farthering-Mystery-2-by-Julianna-Deering.pdf
    • http://loaminoo.linkpc.net/5091090091091/Sunni-The-Life-and-Love-of-King-Tutankhamun-s-Wife-by-Julianna-Boyer.pdf
    • http://loaminoo.linkpc.net/1091093098093091096/Bees-Buzz-by-Pam-Scheunemann.pdf
    • http://loaminoo.linkpc.net/4097090096094098/Day-of-the-Bees-by-Thomas-Sanchez.pdf
    • http://loaminoo.linkpc.net/6098091094095/OBSESSED-The-Compulsions-and-Cr