Malicious PDF — malware analysis report

Static analysis result for SHA-256 6bc25cce13d183fa…

MALICIOUS

PDF

14.7 KB Created: 2019-04-30 02:18:22 +01:00 Authoring application: mPDF 5.7
MD5: d7f3c5d8468be5934293621fa9589390 SHA-1: a315c7a959d70ca8232ee4aa0872e574ce01f98b SHA-256: 6bc25cce13d183fa1e6fa3c400ef8bd1345fb2335a23c0cb5c9610e3a2b19b1f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, many of which are structured as numeric slugs followed by book titles, suggesting an attempt to manipulate search engine results. While the ML classifier flagged the PDF as malicious, the specific intent beyond SEO manipulation is unclear due to the lack of executable scripts or clear malicious document body text. The presence of numerous external links points towards a potential phishing or content redirection scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7096099091090090/The-Active-Interview-by-James-A-Holstein.pdf
    • http://loaminoo.linkpc.net/1091091097093096090/Ace-Your-Teacher-Interview-149-Fantastic-Answers-to-Tough-Interview-Questions-by-Anthony-D-Fredericks.pdf
    • http://loaminoo.linkpc.net/1091091093094093097/The-Forgotten-Terrorist-by-Mel-Ayton.pdf
    • http://loaminoo.linkpc.net/1091091093096094097/The-Irish-Terrorist-by-T-J-Mack.pdf
    • http://loaminoo.linkpc.net/1091091093092093098/The-Terrorist-by-Barry-Levy.pdf
    • http://loaminoo.linkpc.net/4093095097092/Terrorist-by-John-Updike.pdf
    • http://loaminoo.linkpc.net/1090095097090092090/How-Lon-Got-Screwed-by-a-Terrorist-by-E-K-Barone.pdf
    • http://loaminoo.linkpc.net/1091090096091090/The-Terrorist-by-Caroline-B-Cooney.pdf
    • http://loaminoo.linkpc.net/1091091093092093097/The-Terrorist-Next-Door-by-Sheldon-Siegel.pdf
    • http://loaminoo.linkpc.net/1091091093094094096/Spot-the-Terrorist-by-Lori-Jakiela.pdf
    • http://loaminoo.linkpc.net/5090099094093/The-Unseen-Terrorist-by-Oche-Otorkpa.pdf
    • http://loaminoo.linkpc.net/4096095092098092/Intergalactic-Terrorist-New-Dimension-1-by-J-F-Monahan.pdf
    • http://loaminoo.linkpc.net/1091091093096094098/Memoirs-of-an-Italian-Terrorist-by-Giorgio.pdf
    • http://loaminoo.linkpc.net/2096091096097099/The-Good-Terrorist-by-Doris-Lessing.pdf
    • http://loaminoo.linkpc.net/1091091093092098097/Confessions-of-a-Terrorist-A-Novel-by-Richard-Jackson.pdf
    • http://loaminoo.linkpc.net/7090098094094091/The-Black-Terrorist-by-Tierno-Mon-nembo.pdf
    • http://loaminoo.linkpc.net/1091091093092099094/The-Terrorist-Louis-Morgon-3-by-Peter-Steiner.pdf
    • http://loaminoo.linkpc.net/1090098090094091/The-President-The-Terrorist-amp-The-Torturer-by-Jason-Beacon.pdf
    • http://loaminoo.linkpc.net/2099091090094090/The-Last-Station-Master-A-Boy-A-terrorist-A-Secret-And-Trouble-by-S-A-M-Posey.pdf
    • http://loaminoo.linkpc.net/9094097091090096/Der-gute-Terrorist-Ein-Auftrag-f-r-Spenser-by-Robert-B-Parker.pdf