Malicious PDF — malware analysis report

Static analysis result for SHA-256 68f13f2bf0c7e226…

MALICIOUS

PDF

18.2 KB Created: 2019-05-01 08:07:23 +01:00 Authoring application: mPDF 5.7 First seen: 2021-10-14
MD5: 92fc279680bbe5f47e5defbd4e0e223d SHA-1: bc0b34314fb671f06c69deafaf07cb005ba06c88 SHA-256: 68f13f2bf0c7e226b3845b84440e815554cb4486c4959248bdb98f5eb17673d2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which are designed to direct users to external websites. The ML_NYX_PDF_MALICIOUS heuristic also flagged this PDF with high confidence. The embedded URLs are likely part of a link farm intended to drive traffic or potentially lead users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7096094098096093/First-Encounters-A-Book-of-Memorable-Meetings-by-Nancy-Caldwell-Sorel.pdf In PDF document text
    • http://loaminoo.linkpc.net/9091090093096093/Goethe-as-Cultural-Icon-Intertextual-Encounters-with-Stifter-amp-Fontane-by-Nancy-Birch-Wagner.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7096094096090092/Superpen-The-Cartoons-And-Caricatures-Of-Edward-Sorel-by-Edward-Sorel.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090098093092091/Opal-Summerfield-and-The-Battle-of-Fallmoon-Gap-Book-1-by-Mark-Caldwell-Jones.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091098093093092099/Encounters-with-Fire-Encounters-with-People-by-Shiho-Kanzaki.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4096098096097095/Digging-Lifting-the-Memorable-from-Within-the-Unthinkable-by-Susan-Rostan.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090094095097090090/Blue-Lights-In-Your-Mirror-A-Guide-to-the-Criminal-Justice-System-for-Students-Parents-Teachers-and-Coaches-Volume-One-Police-Encounters-Book-1-by-Michael-Hemenway.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5090090099095099/Fictitious-Dishes-An-Album-of-Literature-s-Most-Memorable-Meals-by-Dinah-Fried.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9090090098090097/Nascar-Legends-Memorable-Men-Moments-and-Machines-in-Racing-History-by-Robert-Edelstein.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2090099091097094/Breaking-News-A-Stunning-and-Memorable-Account-of-Reporting-from-Some-of-the-Most-Dangerous-Places-in-the-World-by-Martin-Fletcher.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1096090096097091/The-Rise-of-Alec-Caldwell-Volume-One-The-Rise-of-Alec-Caldwell-1-by-Casey-K-Cox.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1096091092098096/The-Rise-of-Alec-Caldwell-Volume-Two-The-Rise-of-Alec-Caldwell-2-by-Casey-K-Cox.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7096094097095098/See-How-She-Runs-by-Julia-Sorel.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7096094096090098/The-Saturday-Kid-by-Edward-Sorel.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090092095094096/Meetings-With-Remarkable-Men-by-G-I-Gurdjieff.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7096094097091099/Zinfandelity-by-Tracey-Sorel.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4097095095091098/Meetings-with-Morrissey-by-Len-Brown.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1099095096090097/Nocturnal-Meetings-of-the-Misplaced-by-R-J-Garcia.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8092093090090095/Le-complexe-de-Prom-th-e-by-Pierre-Sorel.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7096094096090091/Sorel-Etrog-by-Pierre-Restany.pdfIn PDF document text