Malicious PDF — malware analysis report

Static analysis result for SHA-256 700cec223ba32a4a…

MALICIOUS

PDF

20.7 KB Created: 2019-04-30 05:20:59 +01:00 Authoring application: mPDF 5.7
MD5: 9fb13e830b42c7a29433e010265952d4 SHA-1: d10994fecaaee932c15c5a99e7ddadb1385007ff SHA-256: 700cec223ba32a4aeef95ee558e1088bdc311db692077018e2996d3104377804
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While many of these URLs are marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample, and the document body primarily consists of these URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6096094091094090/Maze-Runner-Parody---The-Dazed-Runner-by-Parody-Brothers.pdf
    • http://loaminoo.linkpc.net/7091090092092099/Maze-Runner-Critique-and-Notes---A-summary-of-James-Dashner-s-The-Maze-Runner-by-Kalilia-Bina.pdf
    • http://loaminoo.linkpc.net/6096094090099098/The-Maze-Runner-and-The-Scorch-Trials-The-Collector-s-Edition-Maze-Runner-1-2-by-James-Dashner.pdf
    • http://loaminoo.linkpc.net/7091090092091096/The-Maze-Runner-3-The-Death-Cure-Movie-Tie-In-by-James-Dashner.pdf
    • http://loaminoo.linkpc.net/1097097099091097/An-Unauthorized-Guide-to-The-Maze-Runner-Movie-The-Film-Based-on-the-Bestselling-James-Dashner-Books-Article-by-D-Carter.pdf
    • http://loaminoo.linkpc.net/5093090093094/Sand-Runner-Sand-Runner-1-by-Vera-Brook.pdf
    • http://loaminoo.linkpc.net/7091090092092098/The-Maze-Runner-by-Jame-Dashner-Book-1-Snapshot-Summary-Companion-Book-by-Snapshot-Books.pdf
    • http://loaminoo.linkpc.net/7091090092092090/JAMES-DASHNER-SERIES-READING-ORDER-THE-MAZE-RUNNER-BOOKS-JIMMY-FINCHER-BOOKS-13TH-REALITY-BOOKS-INFINITY-RING-BOOKS-MORTALITY-DOCTRINE-BOOKS-BY-JAMES-DASHNER-by-List-Series.pdf
    • http://loaminoo.linkpc.net/2093093095094094/Twilite-A-Parody-by-Stephen-Jenner.pdf
    • http://loaminoo.linkpc.net/6098091098093094/Pat-the-Daddy-A-Parody-by-Kate-Merrow-Nelligan.pdf
    • http://loaminoo.linkpc.net/1098096096094097/Goodnight-iPad-A-Parody-for-the-Next-Generation-by-Ann-Droyd.pdf
    • http://loaminoo.linkpc.net/6098091097097096/Pat-the-Husband-A-Parody-by-Kate-Merrow-Nelligan.pdf
    • http://loaminoo.linkpc.net/7097097092090093/50-shades-of-Red-White-and-Blue-A-Parody-by-Leesa-Harker.pdf
    • http://loaminoo.linkpc.net/3090092094092093/The-Taking-Tree-A-Selfish-Parody-by-Shrill-Travesty.pdf
    • http://loaminoo.linkpc.net/4096094092093093/My-Gay-Sparkly-Vampire-Romance-A-Twilight-Parody-by-Zoe-E-Whitten.pdf
    • http://loaminoo.linkpc.net/4093094094091093/The-Best-Case-Scenario-Handbook-A-Parody-by-John-Tierney.pdf
    • http://loaminoo.linkpc.net/1090093091092090097/Divergent-Parody-2-To-Four-With-Love-a-Letter-From-Tris-by-Stir-Ling.pdf
    • http://loaminoo.linkpc.net/9096091091092095/Goodnight-Brew-A-Parody-for-Beer-People-by-Karla-Oceanak.pdf
    • http://loaminoo.linkpc.net/4093099092091092/If-You-Give-a-Kid-a-Cookie-Will-He-Shut-the-F-k-Up-A-Parody-for-Adults-by-Marcy-Roznick.pdf
    • http://loaminoo.linkpc.net/7098099091094092/The-Many-Hues-of-Ted-Cruz-A-Crayon-Erotica-Parody-by-Ennui-Mankini.pdf