Malicious PDF — malware analysis report

Static analysis result for SHA-256 5d58335994991edc…

MALICIOUS

PDF

19.5 KB Created: 2019-04-30 02:44:37 +01:00 Authoring application: mPDF 5.7
MD5: 931c656003495389cbc44adfc9bad3f6 SHA-1: cff769c1070b98d81fbf33d146503f3263298c2c SHA-256: 5d58335994991edc840f1d34802c5e465adce90e002b9760f65d16d07da833cc
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files, characteristic of a link farm designed to drive traffic or potentially distribute further malware. The ML classifier strongly supports a malicious verdict, and the PDF_SEO_LINK_FARM heuristic indicates a deliberate attempt to create a deceptive link structure. No scripts were extracted, and the document body is heavily obfuscated, but the primary malicious behavior observed is the extensive linking.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2096095095091097/Singularity-Sanctuary-series-3-by-Jess-Anastasi.pdf
    • http://loaminoo.linkpc.net/2096095098094090/Sanctuary-Sanctuary-Series-1-by-Jess-Anastasi.pdf
    • http://loaminoo.linkpc.net/9091095093099094/Damage-Control-Valiant-Knox-2-by-Jess-Anastasi.pdf
    • http://loaminoo.linkpc.net/1099096092098098/Jess-and-the-Ghost-of-Black-Rock-Castle-The-Jess-Mystery-Series-Book-1-by-Nina-Levison.pdf
    • http://loaminoo.linkpc.net/3092093094091099/Stories-of-Singularity-Stories-of-Singularity-1-4-by-Susan-Kaye-Quinn.pdf
    • http://loaminoo.linkpc.net/1091095096097097094/459---Framed-in-Red-Book-2-in-the-Mike-Montego-Series-by-Jess-Waid.pdf
    • http://loaminoo.linkpc.net/1090095092098092093/The-Journal-Of-Sanctuary-One-Sanctuary-6-by-R-J-Scott.pdf
    • http://loaminoo.linkpc.net/1090097098096096/The-Last-Sanctuary-The-Last-Sanctuary-1-by-P-S-Mokha.pdf
    • http://loaminoo.linkpc.net/1093093095097094/Orson-Scott-Card-Series-Reading-Order-amp-Checklist-Series-List-in-Order---Ender-Series-Formic-War-Series-Shadow-Series-Ender-Series-amp-Tales-of-Alvin-Maker-Series-Listabook-Series-Order-Book-15-by-Listabook.pdf
    • http://loaminoo.linkpc.net/2090094090098/Sanctuary-Island-Sanctuary-Island-1-by-Lily-Everett.pdf
    • http://loaminoo.linkpc.net/4099092099095/Singularity-by-Bill-DeSmedt.pdf
    • http://loaminoo.linkpc.net/8098090094093092/Beyond-Singularity-by-Jack-Dann.pdf
    • http://loaminoo.linkpc.net/1094090090093/Singularity-by-William-Sleator.pdf
    • http://loaminoo.linkpc.net/1095095093098093/Of-Song-and-Singularity-by-Emory-Skwara.pdf
    • http://loaminoo.linkpc.net/1095093092091097/The-Last-Firewall-Singularity-3-by-William-Hertling.pdf
    • http://loaminoo.linkpc.net/4091091095093095/A-I-Apocalypse-Singularity-2-by-William-Hertling.pdf
    • http://loaminoo.linkpc.net/5094094098094097/Brandon-Mull-Books-Checklist-and-Series-in-Order-2017-Beyonders-Series-in-Order-Candy-Shop-War-Series-in-Order-Dragonwatch-Series-in-Order-Fablehaven-Series-Five-Kingdoms-Series-and-More-by-List-To-Read.pdf
    • http://loaminoo.linkpc.net/3099090098095091/Singularity-Sarah-Armstrong-1-by-Kathryn-Casey.pdf
    • http://loaminoo.linkpc.net/3092091096092093/The-Singularity-Game-Filigree-by-Andrea-K-H-st.pdf
    • http://loaminoo.linkpc.net/4094093098093/The-Singularity-is-Near-When-Humans-Transcend-Biology-by-Ray-Kurzweil.pdf