Malicious PDF — malware analysis report

Static analysis result for SHA-256 550c86d98223e378…

MALICIOUS

PDF

17.5 KB Created: 2019-05-05 16:01:58 +01:00 Authoring application: mPDF 5.7 First seen: 2021-06-04
MD5: 62f7fba0c40b70162534bd9feb5350af SHA-1: bf29c4f869ede59bc3737c3a01a094a69967c296 SHA-256: 550c86d98223e378eaa1f3ebb5d89da93e4d40fce42f1f392e2a77ae556ec8d2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external websites, identified as a 'PDF_SEO_LINK_FARM' heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML classifier also flagged the PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3099095095095096/Around-the-World-in-Seventy-Two-Days-And-Other-Writings-by-Nellie-Bly.pdf In PDF document text
    • http://loaminoo.linkpc.net/4097094090094090/Around-the-World-in-72-Days-by-Nellie-Bly.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3099095090094092/Eighty-Days-Nellie-Bly-and-Elizabeth-Bisland-s-History-Making-Race-Around-the-World-by-Matthew-Goodman.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4092091093091092/Ten-Days-in-a-Mad-House-by-Nellie-Bly.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8092096094094094/Ten-Days-a-Madwoman-The-Daring-Life-and-Turbulent-Times-of-the-Original-quot-Girl-quot-Reporter-Nellie-Bly-by-Deborah-Noyes.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6094090096097095/Last-days-of-Immanuel-Kant-and-other-writings-by-Thomas-de-Quincey.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4095098093093092/Operation-Cowboy-The-Secret-American-Mission-to-Save-the-World-s-Most-Beautiful-Horses-in-the-Last-Days-of-World-War-II-by-Stephan-Talty.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1099092098098090/The-Blazing-World-and-Other-Writings-by-Margaret-Cavendish.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8092097099098091/World-of-Rene-Dubos-A-Collection-from-His-Writings-by-Gerard-Piel.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4097098093096091/Feminism-in-Our-Time-The-Essential-Writings-World-War-II-to-the-Present-by-Miriam-Schneir.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9093098099092/Around-the-World-in-80-Days-by-Marian-Leighton.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6094099094098099/Around-the-World-in-80-Days-by-Jules-Verne.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7092090097094090/Around-the-World-in-80-Days-by-Lo-c-Dauvillier.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6097091098097094/Around-the-World-in-80-Days-Jr-Novel-by-James-Ponti.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090093093090092092/Around-the-World-in-80-Days-by-Jules-Verne.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3094099098097/World-After-Penryn-amp-the-End-of-Days-2-by-Susan-Ee.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4093094099094/World-After-Penryn-amp-the-End-of-Days-2-by-Susan-Ee.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6095099097099092/Around-the-World-in-80-Days-by-Jules-Verne.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3095090093094/At-Seventy-A-Journal-by-May-Sarton.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4099099095091098/Omega-The-Last-Days-of-the-World-by-Camille-Flammarion.pdfIn PDF document text