Malicious PDF — malware analysis report

Static analysis result for SHA-256 53d2d8308ea404a7…

MALICIOUS

PDF

20.3 KB Created: 2019-04-30 18:58:41 +01:00 Authoring application: mPDF 5.7
MD5: f04ebeca56e6d4cfb193991c85cbd617 SHA-1: 778523e3486c309c4d01ccc362356ad557ad6acd SHA-256: 53d2d8308ea404a713ca484a4ff6a03e1faa56d29b451688fd82eda43f90ff3f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a large collection of external PDF links, likely for SEO spam or to host further malicious content. No scripts were extracted, and the document body was heavily corrupted.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4094093093091095/Tiger-s-Heart-The-Story-of-a-Modern-Chinese-Woman-by-Aisling-Juanjuan-Shen.pdf
    • http://loaminoo.linkpc.net/1093098091090092/Almost-a-Revolution-The-Story-of-a-Chinese-Student-s-Journey-from-Boyhood-to-Leadership-in-Tiananmen-Square-by-Shen-Tong.pdf
    • http://loaminoo.linkpc.net/3098093099090097/Sleight-of-Heart-Morality-of-Magick-Book-1-by-Aisling-Mancy.pdf
    • http://loaminoo.linkpc.net/2093093097092096/Trancing-the-Tiger-Chinese-Zodiac-Romance-1-by-Rachael-Slate.pdf
    • http://loaminoo.linkpc.net/1091099091090098096/The-Divinely-Responding-Classic-Shen-Ying-Ching-A-Translation-Of-The-Shen-Ying-Jing-From-The-Zhen-Jiu-Da-Cheng-by-Chi-Chou-Yang.pdf
    • http://loaminoo.linkpc.net/7091095095090098/Sun-Tzu-s-Art-of-War-The-Modern-Chinese-Interpretation-by-Sun-Tzu.pdf
    • http://loaminoo.linkpc.net/5095099097094095/The-Columbia-Anthology-of-Modern-Chinese-Literature-by-Joseph-S-M-Lau.pdf
    • http://loaminoo.linkpc.net/1090097098099094095/Modern-Chinese-Warfare-1795-1989-by-Bruce-A-Elleman.pdf
    • http://loaminoo.linkpc.net/1091097091092098091/Modern-Miracles-The-Story-of-Sathya-Sai-Baba-A-Modern-Day-Prophet-by-Erlendur-Haraldsson.pdf
    • http://loaminoo.linkpc.net/9095093099091096/Chinese-Astrology-Ancient-Secrets-for-Modern-Life-by-Sabrina-Liao.pdf
    • http://loaminoo.linkpc.net/1091094099090097096/Pien-Chih-Lin-A-Study-in-Modern-Chinese-Poetry-by-Lloyd-Haft.pdf
    • http://loaminoo.linkpc.net/1093095093095094/Heart-of-the-Tiger-by-Lindsay-McKenna.pdf
    • http://loaminoo.linkpc.net/7090093094097090/The-Tiger-In-Your-Heart-by-Valerie-Speedwell.pdf
    • http://loaminoo.linkpc.net/3099091093096091/Hoofprint-of-the-Ox-Principles-of-the-Chan-Buddhist-Path-as-Taught-by-a-Modern-Chinese-Master-by-.pdf
    • http://loaminoo.linkpc.net/4092099090093091/The-Heart-of-Chinese-Poetry-by-Greg-Whincup.pdf
    • http://loaminoo.linkpc.net/3094094090090090/The-Tiger-s-Heart-Alaskan-Tigers-2-by-Marissa-Dobson.pdf
    • http://loaminoo.linkpc.net/9098095098092093/Wise-Tiger-It-s-the-wisdom-of-the-heart-that-will-set-you-free-by-Bram-Joosten.pdf
    • http://loaminoo.linkpc.net/3093094099093091/Jennie-s-Tiger-A-Woman-s-Pioneering-Stand-in-an-Untamed-Corner-of-Washington-State-A-Woman-s-Pioneering-Stand-in-an-Untamed-Corner-O-by-Eva-Gayle-Six.pdf
    • http://loaminoo.linkpc.net/4090095096096096/More-Than-Friends---A-Short-Story---by-Alexis-Tiger.pdf
    • http://loaminoo.linkpc.net/1090096096092095091/Integrated-Pharmacology-Combining-Modern-Pharmacology-with-Chinese-Medicine-by-Greg-Sperber.pdf
    • http://loaminoo.linkpc.net/5095099097094095/The-Col