Malicious PDF — malware analysis report

Static analysis result for SHA-256 53e3a05a0adc628f…

MALICIOUS

PDF

21.7 KB Created: 2019-04-30 02:39:26 +01:00 Authoring application: mPDF 5.7
MD5: 9c8e9c0378416ed88c825483eb16d122 SHA-1: 4f45e26fcad2a909e9a2edf6997fcb285c6a6695 SHA-256: 53e3a05a0adc628f177bf7408af16c95023ba3e4a157773c5c874a20ec183eac
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1204.002 Malicious File:Malicious Link

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern appears to be SEO spam or a link farm designed to direct users to external content, potentially malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5096093096091093/A-Princess-of-Mars-Gods-of-Mars-Warlord-of-Mars-Thuvia-Maid-of-Mars-Chessmen-of-Mars-Master-Mind-of-Mars-Fighting-Man-of-Mars-Barsoom-1-7-by-Edgar-Rice-Burroughs.pdf
    • http://loaminoo.linkpc.net/6097096098094094/Mars-Planet-Marsmeteorit-Mars-Trojaner-Darischer-Kalender-Mars-to-Stay-Marskolonisation-Bemannter-Marsflug-Mars-500-Phobos-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/2098090090099090/What-Virtue-There-Is-in-Fire-Cultural-Memory-and-the-Lynching-of-Sam-Hose-by-Edwin-T-Arnold.pdf
    • http://loaminoo.linkpc.net/1090096098090095098/New-Gulliver-Or-the-Adventures-of-Lemuel-Gulliver-Jr-in-Capovolta-by-Esm-Dodderidge.pdf
    • http://loaminoo.linkpc.net/1095099098093090/Red-Mars-Green-Mars-Mars-Trilogy-1-2-by-Kim-Stanley-Robinson.pdf
    • http://loaminoo.linkpc.net/1096092094092091/Amanda-Lester-and-the-Orange-Crystal-Crisis-Amanda-Lester-Detective-2-by-Paula-Berinstein.pdf
    • http://loaminoo.linkpc.net/3095092099098093/Blue-Mars-Mars-Trilogy-3-by-Kim-Stanley-Robinson.pdf
    • http://loaminoo.linkpc.net/5096093096091094/MARS-Horse-With-No-Name-Mars-16-by-Fuyumi-Soryo.pdf
    • http://loaminoo.linkpc.net/5099090096093097/Star-Trek-The-Next-Generation-4-Vol-Boxed-Doomsday-World-12-Exiles-14-Gulliver-s-Doomsday-World-12-Exiles-14-Gulliver-s-by-Silhouette.pdf
    • http://loaminoo.linkpc.net/4099093093092095/Teaching-Your-Child-To-Learn-From-Birth-To-School-Age-by-Arnold-Arnold.pdf
    • http://loaminoo.linkpc.net/8099097096094098/Mars-One-The-Human-Factor-Inside-the-Selection-Adventure-and-Challenges-of-the-First-Human-Settlement-on-Mars-by-Norbert-Kraft.pdf
    • http://loaminoo.linkpc.net/1091098095097096090/Mars---der-W-stenplanet-In-der-Galaxis-Milchstrasse-war-der-Mars-als-der-W-stenplanet-bekannt-by-Walter-Guttropf.pdf
    • http://loaminoo.linkpc.net/1090095095099095099/Arnold-Ruge-Werke-Und-Briefe-5-Zwei-Jahre-in-Paris-1843-1845-by-Arnold-Ruge.pdf
    • http://loaminoo.linkpc.net/1091093098091098098/Arnold-Schoenberg-Wassily-Kandinsky-Letters-Pictures-and-Documents-by-Arnold-Schoenberg.pdf
    • http://loaminoo.linkpc.net/1091093098090099097/Arnold-Schoenberg-Wassily-Kandinsky-Letters-Pictures-and-Documents-by-Arnold-Schoenberg.pdf
    • http://loaminoo.linkpc.net/1091096091091096095/Necropolis-London-and-Its-Dead-by-Catharine-Arnold-2007-Paperback-by-Catharine-Arnold.pdf
    • http://loaminoo.linkpc.net/2093093096096/Collected-Poems-Of-Edwin-Arlington-Robinson-by-Edwin-Arlington-Robinson.pdf
    • http://loaminoo.linkpc.net/2099093094096098/Mars-Evacuees-Mars-Evacuees-1-by-Sophia-McDougall.pdf
    • http://loaminoo.linkpc.net/4095090090091/Saving-Mars-Saving-Mars-1-by-Cidney-Swanson.pdf
    • http://loaminoo.linkpc.net/9097093097093098/Gulliver-s-Travels-by-Pegasus.pdf
    • http://loaminoo.linkpc.net/2098090090099090/What-