Malicious PDF — malware analysis report

Static analysis result for SHA-256 602cf3400165a295…

MALICIOUS

PDF

21.2 KB Created: 2019-04-30 02:05:46 +01:00 Authoring application: mPDF 5.7
MD5: 4478d6a70683c9cbd50b3b7f11dbb7cb SHA-1: c9b1e08aa50c40fd5c58288639d91db561a1efd9 SHA-256: 602cf3400165a295595354f3c1d24987af3ebee43a050079ab3f75b19e3d8911
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting an attempt to direct users to external resources. While the specific URLs extracted were flagged as benign, the sheer volume and the ML classifier's high confidence indicate a malicious intent, likely for phishing or malware distribution. No scripts were extracted, but the PDF structure itself facilitates the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097098097096/The-Fair-and-the-Falls-Spokane-s-Expo-74-Transforming-an-American-Environment-by-J-William-T-Youngs.pdf
    • http://loaminoo.linkpc.net/1090097096099099094/Down-Garden-Paths-The-Floral-Environment-in-American-Art-by-William-H-Gerdts.pdf
    • http://loaminoo.linkpc.net/7092099097094090/The-EXPO-Book---The-Official-Catalogue-of-EXPO-2000-with-CD-ROM-by-Unknown.pdf
    • http://loaminoo.linkpc.net/7092099097093094/Expo-1-Pupil-Book-Expo-11-14-by-Meier.pdf
    • http://loaminoo.linkpc.net/9092097092097092/Strategic-Corporate-Social-Responsibility-Stakeholders-in-a-Global-Environment-by-William-B-Werther-Jr-.pdf
    • http://loaminoo.linkpc.net/9092097094095095/Strategic-Corporate-Social-Responsibility-Stakeholders-in-a-Global-Environment-by-Werther-William-B-Jr-.pdf
    • http://loaminoo.linkpc.net/5095096094094090/The-Progressive-Revolution-in-Politics-and-Political-Science-Transforming-the-American-Regime-by-John-Marini.pdf
    • http://loaminoo.linkpc.net/1090093091092092/The-Wal-Mart-Effect-How-the-World-s-Most-Powerful-Company-Really-Works---and-How-It-s-Transforming-the-American-Economy-by-Charles-Fishman.pdf
    • http://loaminoo.linkpc.net/8090093090092097/Vanity-Fair-by-William-Makepeace-Thackeray.pdf
    • http://loaminoo.linkpc.net/4097097091097093/Vanity-Fair-by-William-Makepeace-Thackeray.pdf
    • http://loaminoo.linkpc.net/2095090098090090/Vanity-Fair-by-William-Makepeace-Thackeray.pdf
    • http://loaminoo.linkpc.net/4096098096099097/Vanity-Fair-by-William-Makepeace-Thackeray.pdf
    • http://loaminoo.linkpc.net/4096094099091092/Vanity-Fair-by-William-Makepeace-Thackeray.pdf
    • http://loaminoo.linkpc.net/8091097092096098/Exploring-the-Chicago-World-s-Fair-1893-American-Sisters-7-by-Laurie-Lawlor.pdf
    • http://loaminoo.linkpc.net/5095096091096096/Vanity-Fair-Jahrmarkt-der-Eitelkeit-by-William-Makepeace-Thackeray.pdf
    • http://loaminoo.linkpc.net/4094096099090092/Divided-Highways-Building-the-Interstate-Highways-Transforming-American-Life-by-Tom-Lewis.pdf
    • http://loaminoo.linkpc.net/1090098094096092098/Vanity-Fair-Audiobook-With-5-Other-Standards-of-English-Literature-by-William-Makepeace-Thackeray.pdf
    • http://loaminoo.linkpc.net/3091098091098098/Falls-The-Shadow-Victor-Carl-5-by-William-Lashner.pdf
    • http://loaminoo.linkpc.net/3091097090093092/The-Regulators-Hell-on-Earth-Part-One-Revised-Edition-by-Douglas-H-Youngs.pdf
    • http://loaminoo.linkpc.net/2096098095093/Mercy-Falls-Cork-O-Connor-5-by-William-Kent-Krueger.pdf