Malicious PDF — malware analysis report

Static analysis result for SHA-256 5fb1c33447ede574…

MALICIOUS

PDF

18.2 KB Created: 2019-04-29 23:05:25 +01:00 Authoring application: mPDF 5.7
MD5: 6f85e0d22b5c87c163f56845825b641d SHA-1: 5ac59ba43f87fd14317a04af6460eb5efff7602d SHA-256: 5fb1c33447ede5742d484c3a540d5c796a83db34e2d4582ad829d776ad7aa573
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier and contains a large number of embedded external links, characteristic of SEO spam or a link farm. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent to manipulate search engine rankings or distribute potentially harmful content. The document body contains these URLs along with metadata, reinforcing the link farm nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091098098092094/The-Second-Lady-by-Irving-Wallace.pdf
    • http://loaminoo.linkpc.net/6091099093091091/The-Three-Sirens-by-Irving-Wallace.pdf
    • http://loaminoo.linkpc.net/7096096098098096/The-R-Document-by-Irving-Wallace.pdf
    • http://loaminoo.linkpc.net/1090097096097099092/The-Fan-Club-by-Irving-Wallace.pdf
    • http://loaminoo.linkpc.net/7092098091091/The-Miracle-by-Irving-Wallace.pdf
    • http://loaminoo.linkpc.net/7093097093097/The-Seven-Minutes-by-Irving-Wallace.pdf
    • http://loaminoo.linkpc.net/3099095090096094/Love-and-Honor-by-Randall-Wallace.pdf
    • http://loaminoo.linkpc.net/1090090098094093091/Successful-Guest-Posting-How-to-Create-Guest-Posts-that-Drive-Traffic-and-Build-Authority-by-Tom-Ewer.pdf
    • http://loaminoo.linkpc.net/4090092095093097/The-Shackled-Continent-Africa-s-Past-Present-and-Future-Robert-Guest-by-Robert-Guest.pdf
    • http://loaminoo.linkpc.net/8095091095091090/The-Sketch-Book-by-Washington-Irving-with-Sketch-of-the-Author-s-Life-and-Compositional-Critical-and-Explanatory-Notes-By-G-A-Chase-by-Washington-Irving.pdf
    • http://loaminoo.linkpc.net/4097094095095094/Moonlight-Murder-The-Last-Poetic-Prose-of-D-B-Wallace-by-D-B-Wallace.pdf
    • http://loaminoo.linkpc.net/6098094092093090/Honor-1-Protect-Serve-Beat-Burn-Honor-1-by-Bill-Jemas.pdf
    • http://loaminoo.linkpc.net/2094091095092090/By-Honor-Bound-Two-Navy-SEALs-the-Medal-of-Honor-and-a-Story-of-Extraordinary-Courage-by-Tom-Norris.pdf
    • http://loaminoo.linkpc.net/3093095090095091/The-Honor-of-the-Queen-Honor-Harrington-2-by-David-Weber.pdf
    • http://loaminoo.linkpc.net/2095099093091090/Echoes-of-Honor-Honor-Harrington-8-by-David-Weber.pdf
    • http://loaminoo.linkpc.net/1094093098099092/The-Honor-of-Spies-Honor-Bound-5-by-W-E-B-Griffin.pdf
    • http://loaminoo.linkpc.net/7096095092095096/Honor-and-Obey-Honor-3-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/2091099096099094/War-of-Honor-Honor-Harrington-10-by-David-Weber.pdf
    • http://loaminoo.linkpc.net/7097094090092/Honor-Student-Honor-1-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/7097090090095092/BEN-HUR-THE-FAIR-GOD-amp-THE-PRINCE-OF-INDIA-or-Why-Constantinople-Fell-LEW-WALLACE-PREMIUM-COLLECTION-Timeless-Wisdom-Collection-Book-1825-by-Lew-Wallace.pdf