Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b95ca3c04bce10f…

MALICIOUS

PDF

17.5 KB Created: 2019-05-04 14:19:28 +01:00 Authoring application: mPDF 5.7
MD5: 425f5b931581e932f386fb78079bc44e SHA-1: e4c92ae6c6e8561bf34eaf58634ca7046f35de96 SHA-256: 5b95ca3c04bce10fc246efbb185e8c269f959a3230b5361980f21a3515e461b7
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. These URLs are hosted on a dynamic DNS domain, suggesting an attempt to distribute malicious content or engage in SEO poisoning. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096091098097091/Urban-Meltdown-Cities-Climate-Change-and-Politics-as-Usual-by-Clive-Doucet.pdf
    • http://loaminoo.linkpc.net/3094091095092098/Requiem-for-a-Species-Why-We-Resist-the-Truth-about-Climate-Change-by-Clive-Hamilton.pdf
    • http://loaminoo.linkpc.net/3094090097094092/Resilient-Cities-Responding-to-Peak-Oil-and-Climate-Change-by-Peter-Newman.pdf
    • http://loaminoo.linkpc.net/3094091093097098/The-Politics-of-Climate-Change-by-Anthony-Giddens.pdf
    • http://loaminoo.linkpc.net/7091093093096090/Climate-Change-and-Energy-Japanese-Perspectives-on-Climate-Change-Mitigation-Strategy-by-Yoichi-Kaya.pdf
    • http://loaminoo.linkpc.net/6095091094090098/Unbuilding-Cities-Obduracy-in-Urban-Sociotechnical-Change-by-Anique-Hommels.pdf
    • http://loaminoo.linkpc.net/7090096097099091/My-Grandfather-s-Cape-Breton-by-Clive-Doucet.pdf
    • http://loaminoo.linkpc.net/7095099095096095/The-Great-Climate-Robbery-How-the-Food-System-Drives-Climate-Change-and-What-We-Can-Do-about-It-by-Grain.pdf
    • http://loaminoo.linkpc.net/6092094095099095/What-We-Know-about-Climate-Change-by-Kerry-Emanuel.pdf
    • http://loaminoo.linkpc.net/6093099090090092/Cities-and-the-Urban-Land-Premium-by-H-L-F-de-Groot.pdf
    • http://loaminoo.linkpc.net/7090099094090099/Trade-and-Climate-Change-by-Ludivine-Tamiotti.pdf
    • http://loaminoo.linkpc.net/1091092092092099/Climate-Change-Turning-Up-the-Heat-by-A-Barrie-Pittock.pdf
    • http://loaminoo.linkpc.net/1091096091090090099/The-Cartoon-Introduction-to-Climate-Change-by-Yoram-Bauman.pdf
    • http://loaminoo.linkpc.net/1091097099093096095/Avoiding-Dangerous-Climate-Change-by-Hans-Joachim-Schellnhuber.pdf
    • http://loaminoo.linkpc.net/1096097093096098/The-Last-Generation-How-Nature-Will-Take-Her-Revenge-for-Climate-Change-by-Fred-Pearce.pdf
    • http://loaminoo.linkpc.net/3094090095090098/Waking-the-Frog-Solutions-for-Our-Climate-Change-Paralysis-by-Tom-Rand.pdf
    • http://loaminoo.linkpc.net/1091098090099092091/Essays-on-Sunbelt-Cities-and-Recent-Urban-America-by-Raymond-A-Mohl.pdf
    • http://loaminoo.linkpc.net/1091093096094095090/Energizing-Sustainable-Cities-Assessing-Urban-Energy-by-Arnulf-Gr-bler.pdf
    • http://loaminoo.linkpc.net/8098092091099094/Cities-for-People-Not-for-Profit-Critical-Urban-Theory-and-the-Right-to-the-City-by-Neil-Brenner.pdf
    • http://loaminoo.linkpc.net/3092098091098092/Hidden-Cities-My-Journey-into-the-Secret-World-of-Urban-Exploration-by-Moses-Gates.pdf