Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ada90922dc92de0…

MALICIOUS

PDF

18.6 KB Created: 2019-04-30 04:32:54 +01:00 Authoring application: mPDF 5.7
MD5: 2c69e232be2813a33f1fc5d48e63153e SHA-1: 62dd90f60b2542e62068cb5454d885a1fc9e0e78 SHA-256: 5ada90922dc92de007ce40aee0c9d9881967cbb2453f6ab3c00f1c9abe3630d4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the document body is heavily obfuscated, the heuristic 'PDF_SEO_LINK_FARM' indicates the primary purpose is to host numerous external links. These links, although currently marked as benign, are structured in a way that suggests they are intended to direct users to potentially malicious content or to manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4094096091097091/Small-Acts-of-Resistance-How-Courage-Tenacity-and-Ingenuity-Can-Change-the-World-by-Steve-Crawshaw.pdf
    • http://loaminoo.linkpc.net/2099093092097092/Small-Change-Small-Change-1-by-Roan-Parrish.pdf
    • http://loaminoo.linkpc.net/7097090090096094/The-Small-Big-Small-Changes-That-Spark-Big-Influence-by-Steve-J-Martin.pdf
    • http://loaminoo.linkpc.net/2094092092090092/Change-The-World-For-Ten-Bucks-50-Actions-To-Change-The-World-And-Make-You-Feel-Great-by-Tim-Ashton.pdf
    • http://loaminoo.linkpc.net/5093097096097096/World-War-2-Heroes-Jean-Moulin-amp-The-French-Resistance-Forces-in-WWII-World-War-2-World-War-II-WWII-WW2-Jean-Moulin-French-Resistance-Book-1-by-Ryan-Jenkins.pdf
    • http://loaminoo.linkpc.net/9095095096097095/Lowenstein-Acts-of-Courage-and-Belief-by-Gregory-Stone.pdf
    • http://loaminoo.linkpc.net/7099095090091098/Alwyn-Crawshaw-Paints-Oils-by-Alwyn-Crawshaw.pdf
    • http://loaminoo.linkpc.net/1095097093091095/Small-Acts-of-Disappearance-by-Fiona-Wright.pdf
    • http://loaminoo.linkpc.net/1093098096098097/Courage-to-Change-by-Al-Anon-Family-Groups.pdf
    • http://loaminoo.linkpc.net/7091097099098090/Change-your-World-Awakening-to-the-Power-of-Truth---Beauty---Simplicity---Change-by-Jean-Maalouf.pdf
    • http://loaminoo.linkpc.net/7099095090092091/Alwyn-Crawshaw-s-Oil-Painting-Course-by-Alwyn-Crawshaw.pdf
    • http://loaminoo.linkpc.net/4092091097091096/Change-Your-Words-Change-Your-World-by-Andrea-Gardner.pdf
    • http://loaminoo.linkpc.net/5090097090093094/Small-Change-Short-Stories-by-Ken-Barris.pdf
    • http://loaminoo.linkpc.net/2096093093094094/Half-a-Crown-Small-Change-3-by-Jo-Walton.pdf
    • http://loaminoo.linkpc.net/1094096098093/Willie-Joe-and-His-Small-Change-by-Marguerite-Vance.pdf
    • http://loaminoo.linkpc.net/3093090091095090/Invitation-to-the-Blues-Small-Change-2-by-Roan-Parrish.pdf
    • http://loaminoo.linkpc.net/1099092096091093/Invitation-to-the-Blues-Small-Change-2-by-Roan-Parrish.pdf
    • http://loaminoo.linkpc.net/4091096090095095/Invitation-to-the-Blues-Small-Change-2-by-Roan-Parrish.pdf
    • http://loaminoo.linkpc.net/7098093096093/10-Things-To-Change-Your-Life-Small-Steps-In-The-Right-Direction-by-Shawn-C-Harris.pdf
    • http://loaminoo.linkpc.net/4094096098098092/100-Ways-to-Motivate-Yourself-Change-Your-Life-Forever-by-Steve-Chandler.pdf