Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f7d32dd47fe00e0…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 18:14:01 +01:00 Authoring application: mPDF 5.7
MD5: 7a2d1b4c10498f79256c01dfa675e002 SHA-1: 00f8d3ff01ff9ce37621c18270c8628fc24bed32 SHA-256: 5f7d32dd47fe00e07521867d7a5f4f0a7e7aa7523e67b20691fda635c0d90d5b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as confirmed benign, the sheer volume and structure suggest an attempt to manipulate search engine results or distribute content through a link farm. The ML_NYX_PDF_MALICIOUS heuristic also flagged the file with high confidence. The embedded links are likely the primary mechanism for the attack, potentially leading to malicious content or further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4098090095/Her-Every-Fear-by-Peter-Swanson.pdf
    • http://loaminoo.linkpc.net/2090097/The-Kind-Worth-Killing-by-Peter-Swanson.pdf
    • http://loaminoo.linkpc.net/6095090094094096/Eles-merecem-a-morte-by-Peter-Swanson.pdf
    • http://loaminoo.linkpc.net/3094092093093098/The-Kind-Worth-Killing-by-Peter-Swanson.pdf
    • http://loaminoo.linkpc.net/1096095096094090/The-Kind-Worth-Killing-by-Peter-Swanson.pdf
    • http://loaminoo.linkpc.net/4099093093097096/The-Kind-Worth-Killing-by-Peter-Swanson.pdf
    • http://loaminoo.linkpc.net/4091090097098090/Great-Irish-Tales-of-Horror-A-Treasury-of-Fear-by-Peter-Haining.pdf
    • http://loaminoo.linkpc.net/4095092095091095/When-Courage-Was-Stronger-Than-Fear-Remarkable-Stories-of-Christians-and-Muslims-Who-Saved-Jews-from-the-Holocaust-by-Peter-Hellman.pdf
    • http://loaminoo.linkpc.net/2097091096098099/Fear-Fighters-How-to-Live-With-Confidence-in-a-World-Driven-by-Fear-by-Jentezen-Franklin.pdf
    • http://loaminoo.linkpc.net/4091093098097/Chill-of-Fear-Bishop-Special-Crimes-Unit-8-Fear-2-by-Kay-Hooper.pdf
    • http://loaminoo.linkpc.net/2094095090091091/Camp-Fear-Ghouls-Ghosts-of-Fear-Street-18-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/5092097096099091/Feel-the-Fear-and-Do-It-Anyway-Dynamic-techniques-for-turning-Fear-Indecision-and-Anger-into-Power-Action-and-Love-by-Susan-Jeffers.pdf
    • http://loaminoo.linkpc.net/3099091098091090/The-Fear-Book-Facing-Fear-Once-and-for-All-by-Cheri-Huber.pdf
    • http://loaminoo.linkpc.net/1092095098090091/Fear-the-Sky-The-Fear-Saga-1-by-Stephen-Moss.pdf
    • http://loaminoo.linkpc.net/3096090095098095/Beauty-of-Fear-Fear-1-by-L-E-Perez.pdf
    • http://loaminoo.linkpc.net/1091098090094094093/Be-Free-from-Fear-Overcoming-Fear-to-Live-Free-by-Denise-Lorenz.pdf
    • http://loaminoo.linkpc.net/3092098096092093/Don-t-Stay-Up-Late-A-Fear-Street-Novel-Fear-Street-Relaunch-2-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/1099099097092096/Earthbound-by-Logan-Swanson.pdf
    • http://loaminoo.linkpc.net/1091099097092099/Earthjoy-by-Anita-Swanson.pdf
    • http://loaminoo.linkpc.net/4098092091091095/Ebony-Eyes-by-Kei-Swanson.pdf