Malicious PDF — malware analysis report

Static analysis result for SHA-256 6554064cb83ac44d…

MALICIOUS

PDF

16.0 KB Created: 2019-05-07 03:42:18 +01:00 Authoring application: mPDF 5.7
MD5: 99fd949dc3d36766caea8984b4d57502 SHA-1: 617321a617aa711acdc51a0f63e216896870252b SHA-256: 6554064cb83ac44d290109f2a605a54ab01ce9d568ea0745d8af4be2033da6be
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, which is a common technique for SEO manipulation or traffic generation. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the sheer volume of links suggests a malicious intent to redirect users to potentially harmful content or to monetize traffic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096096093094098/Changing-Bodies-Changing-Lives-by-Ruth-Bell.pdf
    • http://loaminoo.linkpc.net/4096095097092096/Changing-Planet-Changing-Health-How-the-Climate-Crisis-Threatens-Our-Health-and-What-We-Can-Do-about-It-by-Paul-R-Epstein.pdf
    • http://loaminoo.linkpc.net/7092091098092096/Necessary-Dreams-Ambition-in-Women-s-Changing-Lives-by-Anna-Fels.pdf
    • http://loaminoo.linkpc.net/7092090097090097/PowerMentor-Changing-lives-one-person-at-a-time-The-Art-of-Mentoring-by-Kevin-LaChapelle.pdf
    • http://loaminoo.linkpc.net/1096095097090094/The-Changing-Dynamics-of-Bisexual-Men-s-Lives-Social-Research-Perspectives-by-Eric-Anderson.pdf
    • http://loaminoo.linkpc.net/3092093096095095/The-Changing-Lives-of-Joe-Hart-A-Middle-Falls-Time-Travel-Story-by-Shawn-Inmon.pdf
    • http://loaminoo.linkpc.net/4098091099091098/Changing-My-Wardrobe-by-Deb-Hanrahan.pdf
    • http://loaminoo.linkpc.net/5099092093097091/Changing-Octaves-by-Twinkletail.pdf
    • http://loaminoo.linkpc.net/2096097099093/The-Changing-Land-by-Roger-Zelazny.pdf
    • http://loaminoo.linkpc.net/5097094091097/Being-You-Changing-the-World-by-Dain-Heer.pdf
    • http://loaminoo.linkpc.net/2092092099092098/Changing-Ways-by-Julia-Tannenbaum.pdf
    • http://loaminoo.linkpc.net/4095093099098093/Changing-Spaces-by-Annie-Dyer.pdf
    • http://loaminoo.linkpc.net/2099097092095099/Destiny-Ever-Changing-by-Tasha-Ivey.pdf
    • http://loaminoo.linkpc.net/3097097092091095/Changing-Planes-by-Ursula-K-Le-Guin.pdf
    • http://loaminoo.linkpc.net/1095091093092090/Changing-Patterns-Mary-2-by-Judith-Barrow.pdf
    • http://loaminoo.linkpc.net/5093091091091094/Changing-Moon-A-Tremblay-Pack-Novel-by-Becca-Lee.pdf
    • http://loaminoo.linkpc.net/1091097099094092092/Renovate-Changing-Who-You-Are-by-Loving-Where-You-Are-by-L-once-B-Crump-Jr-.pdf
    • http://loaminoo.linkpc.net/6093091096099097/Rowan-and-Dominic-Changing-The-Game-For-You-1-by-M-L-Bash.pdf
    • http://loaminoo.linkpc.net/9092090095092/Changing-Ways-Book-1-by-Justin-Randall.pdf
    • http://loaminoo.linkpc.net/7097096095093093/The-Changing-Culture-of-a-College-by-John-Frain.pdf