Malicious PDF — malware analysis report

Static analysis result for SHA-256 700f0b8a0728e45b…

MALICIOUS

PDF

16.1 KB Created: 2019-05-07 03:34:58 +01:00 Authoring application: mPDF 5.7
MD5: 7f3552ff21f11b3034068b9b32b42bb7 SHA-1: 864833d64558dd177a3e212fecb5149813fc0649 SHA-256: 700f0b8a0728e45bd07c49097ca81c289527eb22ac26ea7ce780e69184a21adf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files hosted on loaminoo.linkpc.net. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096091099096095/Random-House-Dictionary-of-Abbreviations-by-Random-House.pdf
    • http://loaminoo.linkpc.net/1091093099096092096/Goya-by-Random-House.pdf
    • http://loaminoo.linkpc.net/5093096092091093/Anatole-by-Random-House.pdf
    • http://loaminoo.linkpc.net/9094098096099094/Sinai-The-Desert-amp-Bedouins-of-South-Sinai-s-Central-Regions-by-Ruth-Shilling.pdf
    • http://loaminoo.linkpc.net/6090097099098096/Fernand-Leger-by-Random-House.pdf
    • http://loaminoo.linkpc.net/7094092097092095/Prophecies-Of-Nost-Suede-Fab-B-by-Random-House.pdf
    • http://loaminoo.linkpc.net/1091095092097092098/Register-of-Erotic-Books-by-Random-House.pdf
    • http://loaminoo.linkpc.net/3091093092097093/The-Random-House-Book-of-Poetry-for-Children-by-Jack-Prelutsky.pdf
    • http://loaminoo.linkpc.net/8097090092099092/The-Random-House-Book-of-20th-Century-French-Poetry-by-Paul-Auster.pdf
    • http://loaminoo.linkpc.net/2092096098096095/Random-House-Webster-s-American-Sign-Language-Dictionary-by-Elaine-Costello.pdf
    • http://loaminoo.linkpc.net/1097094093094090/Random-Acts-of-Fantasy-Random-3-Invitation-to-Eden-2-by-Julia-Kent.pdf
    • http://loaminoo.linkpc.net/4098090094090098/Richard-Scarry-s-Great-Steamboat-Mystery-The-Best-Book-Club-Ever-A-Random-House-Picture-Book-by-Richard-Scarry.pdf
    • http://loaminoo.linkpc.net/7097099096095/Random-Passage-Random-Passage-1-by-Bernice-Morgan.pdf
    • http://loaminoo.linkpc.net/9094098096099099/Sinai-Victory-by-S-L-A-Marshall.pdf
    • http://loaminoo.linkpc.net/9094098095097097/Sinai-by-William-Smethurst.pdf
    • http://loaminoo.linkpc.net/1090094097091099/Little-House-in-the-Big-Woods-Farmer-Boy-Little-House-on-the-Prairie-On-the-Banks-of-Plum-Creek-By-the-Shores-of-Silver-Lake-Little-House-1-5-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/9094098096095090/The-Wilderness-of-Sinai-by-Charles-A-Haun.pdf
    • http://loaminoo.linkpc.net/9094098097096097/At-the-Foot-of-Sinai-by-Georges-Clemenceau.pdf
    • http://loaminoo.linkpc.net/9094098095097099/The-Dogs-of-the-Sinai-by-Franco-Fortini.pdf
    • http://loaminoo.linkpc.net/9094098096098097/Mount-Sinai-by-Joseph-J-Hobbs.pdf