Malicious PDF — malware analysis report

Static analysis result for SHA-256 52fc9bf679a86766…

MALICIOUS

PDF

17.7 KB Created: 2019-05-02 02:45:17 +01:00 Authoring application: mPDF 5.7
MD5: ade88586d871e73f5736c58808ce102c SHA-1: e2ee2f34f81c5521930be4dfdc7044a6fc42bdcd SHA-256: 52fc9bf679a8676675e18a96e223f91c1accfc03cc88d008d4d51658034be258
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests a malicious intent, possibly for SEO spam or to redirect users to phishing or malware distribution sites. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8094093091098090/Federal-Electoral-Districts-Representation-Order-of-1996-Circonscriptions-Electorales-Federales-Decret-de-Representation-Electorale-de-1996-by-Elections-Canada.pdf
    • http://loaminoo.linkpc.net/8094093091099094/Federal-Electoral-Districts-Representation-Order-of-1996-Circonscriptions-Electorales-Federales-Decret-de-Representation-Electorale-de-1996-by-Elections-Canada.pdf
    • http://loaminoo.linkpc.net/5097094093094094/Parties-and-Elections-in-America-The-Electoral-Process-by-L-Maisel.pdf
    • http://loaminoo.linkpc.net/6099097092099095/Elections-Electoral-Systems-and-Volatil-by-Gianfranco-Baldini.pdf
    • http://loaminoo.linkpc.net/8095094099093/The-World-as-Will-and-Representation-Vol-2-by-Arthur-Schopenhauer.pdf
    • http://loaminoo.linkpc.net/5097094093095099/Parties-and-Elections-in-America-The-Electoral-Process-by-Mark-D-Brewer.pdf
    • http://loaminoo.linkpc.net/9097092095091098/Thor-1966-1996-456-by-Tom-DeFalco.pdf
    • http://loaminoo.linkpc.net/1091091094094092092/Thor-1966-1996-453-by-Tom-DeFalco.pdf
    • http://loaminoo.linkpc.net/8091095095092092/Bridport-Prize-1996-Sb-by-Mise.pdf
    • http://loaminoo.linkpc.net/1090096092095091099/Thor-1966-1996-454-by-Tom-DeFalco.pdf
    • http://loaminoo.linkpc.net/1090098095096094098/Difference-On-Representation-amp-Sexuality-by-Peter-Wollen.pdf
    • http://loaminoo.linkpc.net/5091098090092091/Sectionalism-And-Representation-In-South-Carolina-by-W-A-Schaper.pdf
    • http://loaminoo.linkpc.net/4096096099094/The-World-as-Will-and-Representation-Volume-1-by-Arthur-Schopenhauer.pdf
    • http://loaminoo.linkpc.net/1091098099096091096/Best-Lesbian-Erotica-1996-by-Tristan-Taormino.pdf
    • http://loaminoo.linkpc.net/6096091092093090/Je-Francois-Mitterrand-1981-1996-by-Wiaz.pdf
    • http://loaminoo.linkpc.net/1091096096099091091/Avengers-1963-1996-377-by-Joey-Cavalieri.pdf
    • http://loaminoo.linkpc.net/5099099090097095/Healthcare-Standards-Directory-1996-by-Ecri.pdf
    • http://loaminoo.linkpc.net/4091095096091094/Looking-beyond-the-frame-racism-representation-amp-resistance-by-Michelle-Reeves.pdf
    • http://loaminoo.linkpc.net/9092092091094091/The-Roles-Of-Representation-In-School-Mathematics-by-Albert-A-Cuoco.pdf
    • http://loaminoo.linkpc.net/5092097098093097/Art-and-Illusion-A-Study-in-the-Psychology-of-Pictorial-Representation-by-E-H-Gombrich.pdf
    • http://loaminoo.linkpc.net/5097094093095099/Parties-and-Elections-in-America-The-Electoral-Process-by-M