Malicious PDF — malware analysis report

Static analysis result for SHA-256 700acc50e23066b8…

MALICIOUS

PDF

23.8 KB Created: 2019-04-30 04:46:55 +01:00 Authoring application: mPDF 5.7
MD5: bdfe2ffd1661719bc2448a7f2ba34af3 SHA-1: aaecd9d4f234081bc0bf5539869bbc519b414d2f SHA-256: 700acc50e23066b8e198cdd712dfd567b8e4f0acd6db96ebf82fc32a0a7cfb39
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. While the URLs themselves are marked as benign, the sheer volume and structure suggest an attempt to manipulate search engine results or distribute content through a link farm. The ML classifier also flagged the PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7096096097099097/Asian-Home-Interior-Decor-by-Miriam-Kinai.pdf
    • http://loaminoo.linkpc.net/8095099091095095/Aromatherapy-Oils-Safety-Precautions-by-Miriam-Kinai.pdf
    • http://loaminoo.linkpc.net/5097091095099091/Find-Faith-Bible-NIV-Verselight-Quickly-Find-Verses-about-God-s-Constant-Faithfulness-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/6094092091096092/Just-Do-Something-How-to-Make-a-Decision-Without-Dreams-Visions-Fleeces-Open-Doors-Random-Bible-Verses-Casting-Lots-Liver-Shivers-Writing-in-the-Sky-etc-by-Kevin-DeYoung.pdf
    • http://loaminoo.linkpc.net/1090097093090098094/Miriam-B-Loo-s-Menu-Planner-Cookbook-by-Miriam-B-Loo.pdf
    • http://loaminoo.linkpc.net/5098095096093093/The-Impatience-Of-Job-by-George-William-Rutler.pdf
    • http://loaminoo.linkpc.net/8090097097092099/King-James-The-Holy-Bible-the-bible-bible-bible-study-jesus-religion-religious-heaven-king-james-old-testament-new-testament-prayer-books-christian-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/2095096093098094/The-Fight-for-Identity-The-Good-Fight-3-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/2095096093096090/The-Fight-Within-The-Good-Fight-2-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/8096098/My-Fight-Your-Fight-by-Ronda-Rousey.pdf
    • http://loaminoo.linkpc.net/3099096092099094/Fight-for-Her-Volume-4-Fight-for-Her-4-by-J-J-Knight.pdf
    • http://loaminoo.linkpc.net/5098095096099097/The-Impatience-Theory-of-Interest-A-Study-of-the-Causes-Determining-the-Rate-of-Interest-by-Irving-Fisher.pdf
    • http://loaminoo.linkpc.net/3094093091096098/Holy-Bible-One-Year-Bible-New-Living-Translation-Compact-Edition-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/1091098098092093093/Read-the-Bible-for-a-Change-A-Follower-s-Guide-to-Reading-and-Responding-to-the-Bible-by-Ray-Lubeck.pdf
    • http://loaminoo.linkpc.net/1091097092090099095/The-Bible-Minute-One-Year-of-Concise-Bible-Studies-for-On-the-Go-Christians-by-Karin-Syren.pdf
    • http://loaminoo.linkpc.net/1091099092097093090/The-Holy-Bible---ESV-Bible-The-Thinline-Edition-TruTone-Espresso-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/2092098097096090/Scientific-Facts-in-the-Bible-100-Reasons-to-Believe-the-Bible-is-Supernatural-in-Origin-by-Ray-Comfort.pdf
    • http://loaminoo.linkpc.net/4092099093093098/The-Bible-s-Cutting-Room-Floor-The-Holy-Scriptures-Missing-from-Your-Bible-by-Joel-M-Hoffman.pdf
    • http://loaminoo.linkpc.net/8096090096098099/The-KJV-Bible-King-James-Bible-Annotated-With-East-chapter-Navigation-Best-for-kindle-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/1091096099099091093/Holy-Bible-New-International-Version-with-concordance-dictionary-maps-and-other-Bible-study-resources-by-Anonymous.pdf