Malicious PDF — malware analysis report

Static analysis result for SHA-256 736d5545491fbb4b…

MALICIOUS

PDF

23.3 KB Created: 2019-05-02 17:03:07 +01:00 Authoring application: mPDF 5.7
MD5: c8ac5f5a3760eeb1509446ab0149e49c SHA-1: 15eec5305ff7d9f1a92007660787484bca4d3fde SHA-256: 736d5545491fbb4bdfcd2f2fc38452959aa35163cb186c9cd2832203c2aa6819
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3092099095098095/Strategy-Safari-A-Guided-Tour-Through-The-Wilds-of-Strategic-Mangament-by-Henry-Mintzberg.pdf
    • http://loaminoo.linkpc.net/3093090095093092/Strategy-Bites-Back-It-Is-Far-More-and-Less-Than-You-Ever-Imagined-by-Henry-Mintzberg.pdf
    • http://loaminoo.linkpc.net/2095096099090099/The-Rise-and-Fall-of-Strategic-Planning-Reconceiving-Roles-for-Planning-Plans-and-Planners-by-Henry-Mintzberg.pdf
    • http://loaminoo.linkpc.net/7091098098094091/PHILADELPHIA-S-ITALIAN-MARKET-TOUR---A-Self-guided-Pictorial-Walking-Tour-Visual-Travel-Tours-Book-107-by-Maria-Liberati.pdf
    • http://loaminoo.linkpc.net/7091098098090094/VENICE-CANALS-amp-STREETS-TOUR---A-Self-guided-Walking-Tour---includes-insider-tips-and-photos-of-all-locations---explore-on-your-own---Like-having-a-friend-show-you-around-by-Maria-Liberati.pdf
    • http://loaminoo.linkpc.net/5093092095094099/Submarine-A-Guided-Tour-Inside-a-Nuclear-Warship-by-Tom-Clancy.pdf
    • http://loaminoo.linkpc.net/1090090097090091092/Readings-in-Strategy-and-Strategic-Management-by-Harry-Costin.pdf
    • http://loaminoo.linkpc.net/5093092096092097/The-Fourth-Dimension-A-Guided-Tour-of-the-Higher-Universes-by-Rudy-Rucker.pdf
    • http://loaminoo.linkpc.net/3098095095090099/Strategy-in-the-Contemporary-World-An-Introduction-to-Strategic-Studies-by-John-Baylis.pdf
    • http://loaminoo.linkpc.net/8096092095098094/Science-Strategy-and-War-The-Strategic-Theory-of-John-Boyd-by-Frans-P-B-Osinga.pdf
    • http://loaminoo.linkpc.net/1091097097099091092/Strategic-Consulting-Tools-and-Methods-for-Successful-Strategy-Missions-by-Philippe-Chereau.pdf
    • http://loaminoo.linkpc.net/6093091095099092/The-master-plan-past-present-and-future-of-the-human-experiment-on-planet-Earth-including-a-guided-tour-of-the-Underworld-by-Hilarion.pdf
    • http://loaminoo.linkpc.net/2095095096092095/The-English-Language-A-Guided-Tour-of-the-Language-by-David-Crystal.pdf
    • http://loaminoo.linkpc.net/5093092095097090/Carrier-A-Guided-Tour-of-an-Aircraft-Carrier-by-Tom-Clancy.pdf
    • http://loaminoo.linkpc.net/4093094090090091/Max-Shulman-s-Guided-Tour-of-Campus-Humor-by-Max-Shulman.pdf
    • http://loaminoo.linkpc.net/9098091098099095/Quarterly-Profits-vs-Long-Term-Strategy-Balancing-Short-Term-Profits-With-Strategic-Growth-by-Lanze-Thompson.pdf
    • http://loaminoo.linkpc.net/1098093095093/ARC-the-Lad-Official-Strategy-Guide-by-Henry-LaPierre.pdf
    • http://loaminoo.linkpc.net/6096093094091093/New-Lanchester-Strategy-Sales-and-Marketing-Strategy-for-the-Strong-by-Shinichi-Yano.pdf
    • http://loaminoo.linkpc.net/5099098094096095/Your-Strategy-Needs-a-Strategy-How-to-Choose-and-Execute-the-Right-Approach-by-Martin-Reeves.pdf
    • http://loaminoo.linkpc.net/7097099090092097/U2-Album-de-U2-Chanson-de-U2-Tournee-de-U2-with-or-Without-You-U2-360-Tour-Vertigo-Tour-I-Still-Haven-t-Found-What-by-Source-Wikipedia.pdf