Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f710dd519e8c21d…

MALICIOUS

PDF

16.2 KB Created: 2019-05-04 14:18:56 +01:00 Authoring application: mPDF 5.7
MD5: 822aaf1fd3c498d6735c41c8d1dca6da SHA-1: bc6a591147fa7ab461f136abc59fad53d64d0f9c SHA-256: 5f710dd519e8c21d61ac1acdabd5d82d684e713623c12746beb281e575fbd116
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. These URLs point to what appear to be book downloads, suggesting a lure to a content-sharing site. The ML classifier also flagged this PDF as malicious, indicating a high probability of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6090098096096/The-Complete-Stories-of-Theodore-Sturgeon-Volume-1-The-Ultimate-Egoist-by-Theodore-Sturgeon.pdf
    • http://loaminoo.linkpc.net/6094090091099095/The-Complete-Stories-of-Theodore-Sturgeon-Volume-III-Killdozer-by-Theodore-Sturgeon.pdf
    • http://loaminoo.linkpc.net/6094090091093093/The-Worlds-of-Theodore-Sturgeon-by-Theodore-Sturgeon.pdf
    • http://loaminoo.linkpc.net/8094094092090098/Mer-n-M-nniska-by-Theodore-Sturgeon.pdf
    • http://loaminoo.linkpc.net/2095091096092/The-Dreaming-Jewels-by-Theodore-Sturgeon.pdf
    • http://loaminoo.linkpc.net/5099096094097093/Edmund-Morris-s-Theodore-Roosevelt-Trilogy-Bundle-The-Rise-of-Theodore-Roosevelt-Theodore-Rex-and-Colonel-Roosevelt-by-Edmund-Morris.pdf
    • http://loaminoo.linkpc.net/3094092090095093/Millie-s-Rose-by-Donna-Sturgeon.pdf
    • http://loaminoo.linkpc.net/3094092097098097/Millie-s-Rose-by-Donna-Sturgeon.pdf
    • http://loaminoo.linkpc.net/1096094097098091/Tale-of-a-Great-White-Fish-A-Sturgeon-Story-by-Maggie-de-Vries.pdf
    • http://loaminoo.linkpc.net/7097092099091096/Theodore-Dreiser---Sister-Carrie-quot-In-Order-to-Have-Wisdom-We-Must-Have-Ignorance-quot-by-Theodore-Dreiser.pdf
    • http://loaminoo.linkpc.net/1090093097098093095/The-Ballades-of-Theodore-de-Banville-by-Th-odore-de-Banville.pdf
    • http://loaminoo.linkpc.net/9096094092090/Theodore-Roosevelt-An-Autobiography-by-Theodore-Roosevelt.pdf
    • http://loaminoo.linkpc.net/2093092099092095/The-Cay-by-Theodore-Taylor.pdf
    • http://loaminoo.linkpc.net/1094094094097/The-Cay-The-Cay-1-by-Theodore-Taylor.pdf
    • http://loaminoo.linkpc.net/1090099098099092/Timothy-of-the-Cay-by-Theodore-Taylor.pdf
    • http://loaminoo.linkpc.net/1096090095096/Outlanders-by-Theodore-Weiss.pdf
    • http://loaminoo.linkpc.net/1096093090093/Praise-to-the-End-by-Theodore-Roethke.pdf
    • http://loaminoo.linkpc.net/1091096099093097092/Banking-by-Theodore-A-Platz.pdf
    • http://loaminoo.linkpc.net/2092092094091096/Kennedy-by-Theodore-C-Sorensen.pdf
    • http://loaminoo.linkpc.net/1093090094092091/Flicker-by-Theodore-Roszak.pdf