Malicious PDF — malware analysis report

Static analysis result for SHA-256 53e00a8e5b5bb99b…

MALICIOUS

PDF

22.6 KB Created: 2019-04-30 04:32:34 +01:00 Authoring application: mPDF 5.7
MD5: d23cce1d4c7753a68335016e52fb21a8 SHA-1: 6a47fe95e776592b11780fea71edc4d84104891b SHA-256: 53e00a8e5b5bb99bc3e2995975aecfab12efe5b7a162072b50b8b3892428890f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which point to external PDF files. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a link farm or SEO poisoning attempt. The ML classifier also flagged this PDF as malicious with high confidence. The document body was unreadable, but the structure indicates a lure to click on these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093095090096/Facing-East-from-Indian-Country-A-Native-History-of-Early-America-by-Daniel-K-Richter.pdf
    • http://loaminoo.linkpc.net/4098096099096098/World-History-Ancient-History-United-States-History-European-Native-American-Russian-Chinese-Asian-Indian-and-Australian-History-Wars-including-World-War-1-and-2-by-Adam-Brown.pdf
    • http://loaminoo.linkpc.net/1091092098095095096/Place-and-Native-American-Indian-History-and-Culture-by-Shamoon-Zamir.pdf
    • http://loaminoo.linkpc.net/4099090096095093/Cultural-Pasts-Essays-in-Early-Indian-History-by-Romila-Thapar.pdf
    • http://loaminoo.linkpc.net/4091095097098097/This-Indian-Country-American-Indian-Activists-and-the-Place-They-Made-by-Frederick-E-Hoxie.pdf
    • http://loaminoo.linkpc.net/7099099094094098/Born-in-the-Country-A-History-of-Rural-America-by-David-B-Danbom.pdf
    • http://loaminoo.linkpc.net/1091093097099099098/The-Birth-of-Motocross-An-Illustrated-History-of-the-Early-Years-of-America-s-1-Dirt-Sport---The-Tracks---The-Riders---The-Machines-by-Robert-Schleichert.pdf
    • http://loaminoo.linkpc.net/2091090098097098/Learning-by-Design-Pacific-Northwest-Coast-Native-Indian-Art-by-Jim-Gilbert.pdf
    • http://loaminoo.linkpc.net/9099098095098098/The-Magic-Bed-A-Book-of-East-Indian-Fairy-Tales-by-Hartwell-James.pdf
    • http://loaminoo.linkpc.net/3096099091094096/Colonial-Intimacies-Indian-Marriage-in-Early-New-England-by-Ann-Marie-Plane.pdf
    • http://loaminoo.linkpc.net/1090095098096097/Changing-Ones-Third-and-Fourth-Genders-in-Native-North-America-by-Will-Roscoe.pdf
    • http://loaminoo.linkpc.net/7096099094092091/A-stranger-in-my-own-country-EAST-PAKISTAN-1969-71-by-Khadim-Hussain-Raja.pdf
    • http://loaminoo.linkpc.net/7090098097094093/Of-Earth-and-Elders-Visions-and-Voices-from-Native-America-by-Serle-Chapman.pdf
    • http://loaminoo.linkpc.net/1090091092094094092/Native-Religions-of-North-America-The-Power-of-Visions-and-Fertility-by-ke-Hultkrantz.pdf
    • http://loaminoo.linkpc.net/2093099094095093/Searching-for-Lost-City-On-the-Trail-of-America-s-Native-Languages-by-Elizabeth-Seay.pdf
    • http://loaminoo.linkpc.net/4090092098094097/The-French-Indian-War-1754-1760-by-Daniel-Marston.pdf
    • http://loaminoo.linkpc.net/1091096094092097093/The-Early-Proterozoic-Richmond-Gulf-Graben-East-Coast-Of-Hudson-Bay-Quebec-by-F-W-Chandler.pdf
    • http://loaminoo.linkpc.net/3093094091099097/Our-Native-Bees-North-America-s-Endangered-Pollinators-and-the-Fight-to-Save-Them-by-Paige-Embry.pdf
    • http://loaminoo.linkpc.net/1090099094097090093/Indian-Skin-Paintings-from-the-American-Southwest-Two-Representations-of-Border-Conflicts-Between-Mexico-and-the-Missouri-in-the-Early-Eighteenth-Century-by-Gottfried-Hotz.pdf
    • http://loaminoo.linkpc.net/7093096096095/High-Country-Summers-The-Early-Second-Homes-of-Colorado-1880-1940-by-Melanie-Shellenbarger.pdf
    • http://loaminoo.linkpc.net/7099099094094098/Born-in-th