Malicious PDF — malware analysis report

Static analysis result for SHA-256 733375b7ea52828f…

MALICIOUS

PDF

17.6 KB Created: 2019-05-07 04:19:38 +01:00 Authoring application: mPDF 5.7
MD5: 3a982ac7ba2feacab86b57e36e1aa915 SHA-1: b884892cfbe0757b5a048db19f391213492f6e84 SHA-256: 733375b7ea52828f0d07f8ab4bae5f1e89279ea64849839e16bad8c3fe20cafd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on loaminoo.linkpc.net, suggesting a link farm or SEO manipulation tactic. While the ML_NYX_PDF_MALICIOUS heuristic strongly indicates maliciousness, the specific intent beyond link farming is unclear without further analysis of the linked PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5090099093091098/The-Lion-Wakes-A-Modern-History-of-HSBC-by-Richard-Roberts.pdf
    • http://loaminoo.linkpc.net/1094092091097092/A-True-Likeness-The-Black-South-of-Richard-Samuel-Roberts-1920-1936-by-Richard-Samuel-Roberts.pdf
    • http://loaminoo.linkpc.net/3099092092097095/Theravada-Buddhism-A-Social-History-from-Ancient-Benares-to-Modern-Colombo-by-Richard-F-Gombrich.pdf
    • http://loaminoo.linkpc.net/1095090094098090/A-Second-Daniel-In-the-Den-of-the-English-Lion-1-by-Neal-Roberts.pdf
    • http://loaminoo.linkpc.net/1092097091093090/Operation-Sea-Lion-by-Richard-Hubert-Francis-Cox.pdf
    • http://loaminoo.linkpc.net/5095096095094095/The-Off-Modern-Psychology-Estranged-by-Ron-Roberts.pdf
    • http://loaminoo.linkpc.net/2090093092092091/Quite-Contrary-by-Richard-Roberts.pdf
    • http://loaminoo.linkpc.net/7095094099097/Please-Don-t-Tell-My-Parents-You-Believe-Her-by-Richard-Roberts.pdf
    • http://loaminoo.linkpc.net/8099090097091096/Schroders-Merchants-amp-Bankers-by-Richard-Roberts.pdf
    • http://loaminoo.linkpc.net/4090092094090096/The-Penguin-History-of-the-World-by-J-M-Roberts.pdf
    • http://loaminoo.linkpc.net/5091094097099090/The-Unnatural-History-of-the-Sea-by-Callum-Roberts.pdf
    • http://loaminoo.linkpc.net/2097097098097090/The-Penguin-History-of-the-World-by-J-M-Roberts.pdf
    • http://loaminoo.linkpc.net/8098090092097097/A-History-of-New-York-in-101-Objects-by-Sam-Roberts.pdf
    • http://loaminoo.linkpc.net/5090099093092090/Saving-the-City-The-Great-Financial-Crisis-of-1914-by-Richard-Roberts.pdf
    • http://loaminoo.linkpc.net/6097096098094090/Red-Lion-Blue-Lion-WARS-The-Battle-of-Phobos---Gongen-Part-2-of-3-by-Sabrina-Fried.pdf
    • http://loaminoo.linkpc.net/2095093095095098/A-Lion-Called-Christian-The-True-Story-of-the-Remarkable-Bond-Between-Two-Friends-and-a-Lion-by-Anthony-Bourke.pdf
    • http://loaminoo.linkpc.net/5091092095093093/3-1-3-gatsu-no-Lion-1-March-comes-in-like-a-lion-1-by-Chica-Umino.pdf
    • http://loaminoo.linkpc.net/4095098099092096/Modern-Poems-An-Introduction-to-Poetry-by-Richard-Ellmann.pdf
    • http://loaminoo.linkpc.net/4098098099095/A-History-of-the-English-Speaking-Peoples-Since-1900-by-Andrew-Roberts.pdf
    • http://loaminoo.linkpc.net/3092098091098094/Alone-on-the-Ice-The-Greatest-Survival-Story-in-the-History-of-Exploration-by-David-Roberts.pdf