Malicious PDF — malware analysis report

Static analysis result for SHA-256 70c5c36dc2eb91a5…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 03:34:13 +01:00 Authoring application: mPDF 5.7
MD5: 8808c5bc54b8ca32eac175604c153aad SHA-1: b66dfd82a318695007d865ca40e558fd9d925d48 SHA-256: 70c5c36dc2eb91a52642b072d8f6166533af0e4a930d5052004c2818c8f403b9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the document body is heavily obfuscated, the presence of numerous external links suggests a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097094092091092/The-Geographical-Reading-Book-by-T-Crampton-and-T-Turner-by-Thomas-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094090096097/Bulgaria-by-R-J-Crampton.pdf
    • http://loaminoo.linkpc.net/7097093099099096/The-Sunburnt-Queen-by-Hazel-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094090090090/A-Concise-History-of-Bulgaria-by-R-J-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094092091093/Complete-Trash-by-Norm-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094091097094/How-to-Be-a-Beta-Male-by-Robert-Crampton.pdf
    • http://loaminoo.linkpc.net/8094091094098090/The-Trebor-Story-by-Matthew-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094090095093/Writers-Photographs-by-Nancy-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094090096095/100-Best-Small-Towns-in-America-Rated-by-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094091096090/Flag-Eyewitness-Books-by-William-G-Crampton.pdf
    • http://loaminoo.linkpc.net/7096091095097097/Flag-Eyewitness-Books-by-William-G-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094090095091/Eastern-Europe-in-the-Twentieth-Century---And-After-by-Richard-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094091096092/Atlas-of-Eastern-Europe-in-the-Twentieth-Century-by-Richard-Crampton.pdf
    • http://loaminoo.linkpc.net/7097094090095094/Green-House-Eco-Friendly-Disposal-and-Recycling-at-Home-by-Norm-Crampton.pdf
    • http://loaminoo.linkpc.net/7097093099099093/Stop-Press-Murder-Crampton-of-The-Chronicle-Mystery-2-by-Peter-Bartram.pdf
    • http://loaminoo.linkpc.net/7097094090090093/The-Tango-School-Mystery-A-Crampton-of-the-Chronicle-adventure-Deadline-Murder-series-1-by-Peter-Bartram.pdf
    • http://loaminoo.linkpc.net/7097094092091091/Crampton-s-Hygiene-Series-Hygiene-for-the-Worker-by-William-H-Tolman.pdf
    • http://loaminoo.linkpc.net/7097094092090094/Mapping-A-Critical-Introduction-to-Cartography-and-GIS-A-Critical-Introduction-to-GIS-and-Cartography-by-Jeremy-W-Crampton.pdf
    • http://loaminoo.linkpc.net/4094091096093097/Thomas-Of-Reading-by-Thomas-Deloney.pdf
    • http://loaminoo.linkpc.net/1091090096094098093/Reading-The-Nibelungenlied-by-Neil-Thomas.pdf