Malicious PDF — malware analysis report

Static analysis result for SHA-256 52dc4e5b6d99599b…

MALICIOUS

PDF

20.6 KB Created: 2019-04-30 04:02:40 +01:00 Authoring application: mPDF 5.7
MD5: 9f2d5a093981d1dc536ebe1adbdf2634 SHA-1: 10d5154b92f53cea72f1f67c6cbe2819d813a4af SHA-256: 52dc4e5b6d99599ba7185a28201e0c02623ddb14d6f36e503b33b654d147d9ed
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign-looking book titles, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090090098096099091/Beyond-the-Broomstick-Thoughts-on-the-Philosophy-of-Wicca-by-Morgana-Sythove.pdf
    • http://loaminoo.linkpc.net/6097092094093096/Wicca-Book-of-Spells-A-Spellbook-for-Beginners-to-Advanced-Wiccans-Witches-and-other-Practitioners-of-Magic-Wicca-Books-Wicca-Spells-1-by-Leonie-Sage.pdf
    • http://loaminoo.linkpc.net/4090096098094094/Wicca-for-Beginners-Fundamentals-of-Philosophy-amp-Practice-by-Thea-Sabin.pdf
    • http://loaminoo.linkpc.net/9098090094093095/Getting-Our-Thoughts-Together-Instructional-Manual-to-Accompany-Elfie-Philosophy-for-Children-1-by-Matthew-Lipman.pdf
    • http://loaminoo.linkpc.net/4098094091092090/Wicca-Love-Spells-Powerful-Wicca-Love-Spells-That-Really-Work-by-Aurora-Rede.pdf
    • http://loaminoo.linkpc.net/1096098095099097/Cat-on-a-Broomstick-by-Joanne-Marshall.pdf
    • http://loaminoo.linkpc.net/2097097095098094/Broomstick-Breakdown-by-Eve-Langlais.pdf
    • http://loaminoo.linkpc.net/4090091099092098/The-Little-Broomstick-by-Mary-Stewart.pdf
    • http://loaminoo.linkpc.net/6096096097099/Bedknob-and-Broomstick-by-Mary-Norton.pdf
    • http://loaminoo.linkpc.net/9095094097097092/The-Philosophy-of-Computer-Games-7-Philosophy-of-Engineering-and-Technology-by-John-Richard-Sageng.pdf
    • http://loaminoo.linkpc.net/6095093094091099/Introduction-to-the-Philosophy-of-History-with-Selections-from-The-Philosophy-of-Right-by-Georg-Wilhelm-Friedrich-Hegel.pdf
    • http://loaminoo.linkpc.net/1090094095091094097/Philosophy-in-the-Islamic-World-A-History-of-Philosophy-Without-Any-Gaps-3-by-Peter-Adamson.pdf
    • http://loaminoo.linkpc.net/9092095097095094/Stephen-Colbert-and-Philosophy-I-Am-Philosophy-by-Aaron-Allen-Schiller.pdf
    • http://loaminoo.linkpc.net/1090094095090097099/Classical-Philosophy-A-History-of-Philosophy-Without-Any-Gaps-1-by-Peter-Adamson.pdf
    • http://loaminoo.linkpc.net/3094095092099090/The-Ultimate-Star-Wars-and-Philosophy-You-Must-Unlearn-What-You-Have-Learned-The-Blackwell-Philosophy-and-Pop-Culture-Series-by-Jason-T-Eberl.pdf
    • http://loaminoo.linkpc.net/8094091091091094/Kierkegaard-s-Influence-on-Philosophy-Francophone-Philosophy-by-Jon-Stewart.pdf
    • http://loaminoo.linkpc.net/1090090098092093091/Morgana-by-A-D-Swift.pdf
    • http://loaminoo.linkpc.net/6092094098099096/Wicca-5-by-Cate-Tiernan.pdf
    • http://loaminoo.linkpc.net/9099095090097093/Fata-Morgana-by-Jon-Vermilyea.pdf
    • http://loaminoo.linkpc.net/3091093090090098/Pax-Morgana-by-Bill-Coffin.pdf
    • http://loaminoo.linkpc.net