Malicious PDF — malware analysis report

Static analysis result for SHA-256 67698f93b0e0e4df…

MALICIOUS

PDF

21.1 KB Created: 2019-04-30 02:55:54 +01:00 Authoring application: mPDF 5.7
MD5: 9ee13b238f65cea5fb504f7c1ab723bc SHA-1: d4639c7439e2f7e4072ae127dd2cbf1df16d998a SHA-256: 67698f93b0e0e4df61e000d4baa664585dcc23ddea2c9fec6db62c21b1d868bd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF was flagged by a machine learning classifier and contains a large number of embedded external links, many of which point to book-related PDFs. The heuristic PDF_SEO_LINK_FARM indicates a potential attempt to manipulate search engine results or distribute content through a link farm. The document body is heavily obfuscated and unreadable, providing no further context on its specific intent beyond the link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093097096094090/Algorithms-Plus-Data-Structures-Equals-Programs-Prentice-Hall-series-in-automatic-computation-by-Niklaus-Wirth.pdf
    • http://loaminoo.linkpc.net/1091093097096094095/Algorithms-amp-Data-Structures-by-Niklaus-Wirth.pdf
    • http://loaminoo.linkpc.net/1091092090091097096/Data-Structures-and-Algorithms-Made-Easy-in-Java-700-Data-Structure-and-Algorithmic-Puzzles-by-Narasimha-Karumanchi.pdf
    • http://loaminoo.linkpc.net/1091092090090099099/Data-Structures-and-Algorithms-in-Java-by-Robert-Lafore.pdf
    • http://loaminoo.linkpc.net/1090092094098094096/DNA-Complex-and-Adaptive-Behaviour-Prentice-Hall-series-in-experimental-psychology-by-John-Gaito.pdf
    • http://loaminoo.linkpc.net/1091091093094092095/Integrated-Digital-Electronics-Prentice-Hall-series-in-electronic-technology-by-Walter-A-Treibel.pdf
    • http://loaminoo.linkpc.net/9096099093098096/An-introduction-to-animal-behavior-Ethology-s-first-century-Prentice-Hall-biological-science-series-by-Peter-H-Klopfer.pdf
    • http://loaminoo.linkpc.net/1092092098094090/Genetic-Programming-II-Automatic-Discovery-of-Reusable-Programs-by-John-R-Koza.pdf
    • http://loaminoo.linkpc.net/1091092090090095091/Data-Structures-Using-C-by-Reema-Thareja.pdf
    • http://loaminoo.linkpc.net/1090096099095099090/Data-Clustering-Theory-Algorithms-and-Applications-by-Guojun-Gan.pdf
    • http://loaminoo.linkpc.net/9099090090099096/Walcom-Algorithms-and-Computation-12th-International-Conference-Walcom-2018-Dhaka-Bangladesh-March-3-5-2018-Proceedings-by-M-Sohel-Rahman.pdf
    • http://loaminoo.linkpc.net/9094097094092095/Data-Structures-and-Program-Design-in-C-by-Robert-L-Kruse.pdf
    • http://loaminoo.linkpc.net/1091092090090094092/Purely-Functional-Data-Structures-by-Chris-Okasaki.pdf
    • http://loaminoo.linkpc.net/1091098091093099090/Delfines-by-Prentice-Hall-Pearson.pdf
    • http://loaminoo.linkpc.net/5093091091093091/An-Introduction-to-Data-Structures-with-Applications-by-Jean-Paul-Tremblay.pdf
    • http://loaminoo.linkpc.net/8095091096098091/Prentice-Hall-Grammar-and-Composition-4-by-Gary-Forlini.pdf
    • http://loaminoo.linkpc.net/7097099092093091/Laplace-Transforms-and-an-Introduction-to-Distributions-by-Prentice-Hall.pdf
    • http://loaminoo.linkpc.net/1090093091099092099/Treffpunkt-Deutsch-Grundstufe-amp-1key-CC-Pkg-by-Prentice-Hall-Pearson.pdf
    • http://loaminoo.linkpc.net/7091091096098090/CENTER-FOR-MATHEMATICS-EDUCATION-ALGEBRA-1-TEACHER-EXPRES-CD-ROM-by-Prentice-Hall.pdf
    • http://loaminoo.linkpc.net/5096090093095093/Amer-Peo-Creatg-V2-Vango-amp-carng-amp-e-Rsvlt-amp-mhk-by-Prentice-Hall-Pearson.pdf