Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f34fbfa66d30620…

MALICIOUS

PDF

17.4 KB Created: 2019-05-05 14:05:15 +01:00 Authoring application: mPDF 5.7 First seen: 2021-08-20
MD5: 2e13b40102b6b5691581008e811f8446 SHA-1: 81e9b8036e88c4ab86b94784c825963fc86124b3 SHA-256: 5f34fbfa66d30620a32eaf0bd5d19a6406ae2218db4cfc4870f82f5dbe34267f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles, but the sheer volume and the use of a dynamic DNS hostname suggest a malicious intent, possibly for SEO manipulation or to distribute malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3095095090094/Bright-Side-Bright-Side-1-by-Kim-Holden.pdf In PDF document text
    • http://loaminoo.linkpc.net/6099093094093/Bright-Side-Bright-Side-1-by-Kim-Holden.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1096097098091090/Gus-Bright-Side-2-by-Kim-Holden.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4096093094099092/Franco-Bright-Side-3-by-Kim-Holden.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3098098092092097/On-The-Bright-Side-by-S-R-Johannes.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2091097099096099/The-Bright-Side-Of-Disaster-by-Katherine-Center.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9090099095/Always-Look-on-the-Bright-Side-of-Life-A-Sortabiography-by-Eric-Idle.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2096098096095093/Be-a-Unicorn-and-Live-Life-on-the-Bright-Side-by-Sarah-Ford.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3095095092093095/And-the-Good-News-Is-Lessons-and-Advice-from-the-Bright-Side-by-Dana-Perino.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3099096090091095/Bright-Beyond-Episode-1-Bright-Beyond-1-by-Theresa-Kay.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1097099096095/Side-by-Side-Leadership-Achieving-Outstanding-Results-Together-by-Dennis-A-Romig.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9093091093090096/Three-Translations-of-the-Koran-Al-Qur-an---Side-by-Side-with-Each-Verse-Not-Split-Across-Pages-by-Anonymous.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5091097099091094/Claiming-Abraham-Reading-the-Bible-and-the-Qur-an-Side-by-Side-by-Michael-E-Lodahl.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091090093098095096/Side-by-Side-The-Revolutionary-Mother-Daughter-Program-for-Conflict-Free-Communication-by-Charles-Sophy.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1098095094091/Photoshop-Painter-Illustrator-Side-By-Side-by-Wendy-Crumpler.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1096090097095092/The-Other-Side-The-Other-Side-Trilogy-Book-1-by-Anna-Marie-McIntyre.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8094090094095/The-Dark-Side-of-Midnight-Featuring-The-Other-Side-of-Midnight-Rage-of-Angels-Bloodline-by-Sidney-Sheldon.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2099094090091095/Side-by-Side-by-Jenni-L-Walsh.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3092092092094091/Other-Side-of-Night-Bastian-amp-Riley-Other-Side-of-Night-1-by-S-L-Armstrong.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4098095092/The-Girl-from-the-Other-Side-Si-il-A-R-n-Volume-1-The-Girl-from-the-Other-Side-1-by-Nagabe.pdfIn PDF document text