Malicious PDF — malware analysis report

Static analysis result for SHA-256 6a1d30bb399b5098…

MALICIOUS

PDF

20.8 KB Created: 2019-04-30 04:54:20 +01:00 Authoring application: mPDF 5.7
MD5: cf845b4f344edde4cea826faa3bde8f5 SHA-1: e0d1a3e65b6e897ea7974d64b8c15a665efe85da SHA-256: 6a1d30bb399b5098bcd2b3eed9524d9ffcb749cd32dc3c22ccf3c77da3b51aff
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates this is a common tactic for SEO manipulation or potentially distributing malicious content. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to redirect users. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3099091092095098/Code-Name-Atlas-by-Tony-Evans.pdf
    • http://loaminoo.linkpc.net/5095098097092095/The-Emoji-Code-Language-and-the-Nature-of-Communication-by-Vyvyan-Evans.pdf
    • http://loaminoo.linkpc.net/7098092095098098/The-Electrician-s-Code-An-Evans-and-Blackwell-Mystery-by-Clarissa-Draper.pdf
    • http://loaminoo.linkpc.net/7094090094092/Time-to-Get-Serious-Daily-Devotions-to-Keep-You-Close-to-God-by-Tony-Evans.pdf
    • http://loaminoo.linkpc.net/3096095098092098/Victory-in-Spiritual-Warfare-Outfitting-Yourself-for-the-Battle-by-Tony-Evans.pdf
    • http://loaminoo.linkpc.net/1090096091090091097/The-Soho-Anarchist-The-Hester-Lynton-Mysteries-2-by-Tony-Evans.pdf
    • http://loaminoo.linkpc.net/3096093097095096/Kingdom-Woman-Embracing-Your-Purpose-Power-and-Possibilities-by-Tony-Evans.pdf
    • http://loaminoo.linkpc.net/1091097095098096098/An-Atlas-of-Functions-With-Equator-the-Atlas-Function-Calculator-by-Jerome-Spanier.pdf
    • http://loaminoo.linkpc.net/7097094098097094/Atlas-Historique-du-Golfe-Persique-Xvie-Xviiie-Siecles---Historical-Atlas-of-the-Persian-Gulf-by-Zoltan-Biedermann.pdf
    • http://loaminoo.linkpc.net/1090097094091092097/Ausgewahlte-gynako-urologische-Operationen-Anhang-Durchzugspyelonephrostomie-mittels-U-Drain-Atlas-Selected-urologic-operations-in-gynecology-annex-U-tube-pyelonephrostomy-atlas-by-Herbert-Janisch.pdf
    • http://loaminoo.linkpc.net/1095095093094098/ATLAS-2-Atlas-2-by-Isaac-Hooke.pdf
    • http://loaminoo.linkpc.net/6096091094/Code-Girls-The-Untold-Story-of-the-American-Women-Code-Breakers-Who-Helped-Win-World-War-II-by-Liza-Mundy.pdf
    • http://loaminoo.linkpc.net/1098091095094092/Code-Name-Nanny-SEAL-and-Code-Name-5-by-Christina-Skye.pdf
    • http://loaminoo.linkpc.net/8094095098097/Code-Name-Baby-SEAL-and-Code-Name-7-by-Christina-Skye.pdf
    • http://loaminoo.linkpc.net/3099096090096097/Code-Name-Bundle-Includes-Code-Name-3-5-by-Christina-Skye.pdf
    • http://loaminoo.linkpc.net/3098093090094092/The-Friendship-Code-Girls-Who-Code-1-by-Stacia-Deutsch.pdf
    • http://loaminoo.linkpc.net/9095099091096093/A-Code-Of-Love-Code-Breakers-1-by-Jacki-Delecki.pdf
    • http://loaminoo.linkpc.net/1091095092098095094/The-Code-Red-Revolution-How-Thousands-of-People-are-Losing-Weight-and-Keeping-it-Off-WITHOUT-Pills-Shakes-Diet-Foods-or-Exercise-by-Cristy-Code-Red-Nickel.pdf
    • http://loaminoo.linkpc.net/1092095097095097/The-Bar-Code-Prophecy-Bar-Code-3-by-Suzanne-Weyn.pdf
    • http://loaminoo.linkpc.net/4091094090091091/The-Leader-Code-Crack-this-once-hidden-code-to-become-an-effective-leader-by-Dan-Blakeslee.pdf