Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f7c5cf07360e0d3…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 05:57:48 +01:00 Authoring application: mPDF 5.7
MD5: c0201375c54876272469d3503e29efed SHA-1: 5aa285036495e03f7e1f560401235359790e8287 SHA-256: 5f7c5cf07360e0d32a5affcaeb9da913d3c3f4708bcc7b41cc31d885a3a386b4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, constituting a link farm. The primary heuristic indicates this is a malicious SEO tactic, likely intended to drive traffic to external sites. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent to redirect users. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7095098094091097/Mohammed-and-the-Unbelievers-by-Cspi.pdf
    • http://loaminoo.linkpc.net/9094097096090098/The-Unbelievers-by-Trevor-Smith.pdf
    • http://loaminoo.linkpc.net/9094097097090094/Unbelievers-or-The-Moor-by-John-Mateer.pdf
    • http://loaminoo.linkpc.net/9094097097091097/Traps-for-Unbelievers-by-Mary-Butts.pdf
    • http://loaminoo.linkpc.net/9094097097091095/Insight-of-Unbelievers-by-Deeana-Klepper.pdf
    • http://loaminoo.linkpc.net/9094097097092090/Arabic-for-Unbelievers-by-Peter-Townsend.pdf
    • http://loaminoo.linkpc.net/9094097098093097/Hell-The-Final-Destination-For-Unbelievers-by-Don-Stewart.pdf
    • http://loaminoo.linkpc.net/9094097097093093/The-Unbelievers-A-Truman-Tames-Novel-by-Steven-Myers.pdf
    • http://loaminoo.linkpc.net/9094097098093096/A-Serious-Charge-against-Unbelievers-by-Charles-Haddon-Spurgeon.pdf
    • http://loaminoo.linkpc.net/9094097097092098/Catholics-and-Unbelievers-in-18th-Century-France-by-R-R-Palmer.pdf
    • http://loaminoo.linkpc.net/9094097098094095/The-Beginning-Genesis-The-Bible-for-Unbelievers-1-by-Guus-Kuijer.pdf
    • http://loaminoo.linkpc.net/9094097098095093/Mohammed-and-the-Unbelievers-The-Sira-a-Political-Biography-by-Bill-Warner.pdf
    • http://loaminoo.linkpc.net/9094097098095095/The-Gifts-of-the-Holy-Spirit-to-Unbelievers-and-Believers-by-Clement-Read-Vaughan.pdf
    • http://loaminoo.linkpc.net/3098096091099/Julie-and-Julia-365-Days-524-Recipes-1-Tiny-Apartment-Kitchen-by-Julie-Powell.pdf
    • http://loaminoo.linkpc.net/2099093094094099/Julie-amp-Julia-365-days-524-recipes-1-tiny-apartment-kitchen-by-Julie-Powell.pdf
    • http://loaminoo.linkpc.net/1094092095097090/Julie-and-the-Eagles-American-Girls-Julie-4-by-Megan-McDonald.pdf
    • http://loaminoo.linkpc.net/1094092095090091/Julie-s-Journey-American-Girls-Julie-5-by-Megan-McDonald.pdf
    • http://loaminoo.linkpc.net/1094092094091097/Changes-for-Julie-American-Girls-Julie-6-by-Megan-McDonald.pdf
    • http://loaminoo.linkpc.net/4099098091093095/Village-Atheists-How-America-s-Unbelievers-Made-Their-Way-in-a-Godly-Nation-by-Leigh-Eric-Schmidt.pdf
    • http://loaminoo.linkpc.net/9094097098094094/Precious-Remedies-Against-Satans-Device-Or-Salve-for-Believers-amp-Unbelievers-Sores-by-Thomas-Brookes-1656-by-Thomas-Brooks.pdf