Malicious PDF — malware analysis report

Static analysis result for SHA-256 73985943b31e5792…

MALICIOUS

PDF

25.8 KB Created: 2019-04-30 04:20:29 +01:00 Authoring application: mPDF 5.7
MD5: 5c3e2bc2e05d3a88464e701080bcdf94 SHA-1: 91a06e15a9ab916305e66784dafff0daf8bc9f89 SHA-256: 73985943b31e5792d2d1ddf462cb200b9e2e716956073e872b1bb22c42c83769
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier also flagged this document as malicious. The primary attack pattern involves directing users to a link farm hosted on a dynamic DNS domain, likely as a precursor to a more harmful payload or phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4096096099095093/The-Little-Wild-Ponies-by-Sonja-Bullaty.pdf
    • http://loaminoo.linkpc.net/9099096095092090/102-Minuten-Die-nie-erz-hlte-Geschichte-vom-Kampf-ums-berleben-in-den-T-rmen-des-World-Trade-Center-by-Jim-Dwyer.pdf
    • http://loaminoo.linkpc.net/3091099095094093/The-War-Against-America-Saddam-Hussein-and-the-World-Trade-Center-Attacks-A-Study-of-Revenge-by-Laurie-Mylroie.pdf
    • http://loaminoo.linkpc.net/2095093090090095/The-World-That-Trade-Created-Society-Culture-and-the-World-Economy-1400-to-the-Present-by-Kenneth-Pomeranz.pdf
    • http://loaminoo.linkpc.net/9097098099090093/World-War-II-Remembered-History-in-Your-Hands-a-Numismatic-Study-by-Fred-Schwan.pdf
    • http://loaminoo.linkpc.net/2095092094099092/Flying-Cars-Zombie-Dogs-and-Robot-Overlords-How-World-s-Fairs-and-Trade-Expos-Changed-the-World-by-Charles-Pappas.pdf
    • http://loaminoo.linkpc.net/4095098099095091/Secrets-from-the-Center-of-the-World-by-Joy-Harjo.pdf
    • http://loaminoo.linkpc.net/1090093093093097093/The-Center-of-the-World-by-Thomas-Van-Essen.pdf
    • http://loaminoo.linkpc.net/1093097095099091/Op-Center-Tom-Clancy-s-Op-Center-1-by-Jeff-Rovin.pdf
    • http://loaminoo.linkpc.net/5094098097092091/Trade-And-Competition-Policies-Comparing-Objectives-And-Methods-Trade-Policy-Issues-No-4-by-Phedon-Nicolaides.pdf
    • http://loaminoo.linkpc.net/1091090091095091099/The-Politics-of-Transatlantic-Trade-Negotiations-Ttip-in-a-Globalized-World-by-Jean-Fr-d-ric-Morin.pdf
    • http://loaminoo.linkpc.net/1096091090092093/Extraordinary-Voyages-Around-the-World-in-Eighty-Days-Journey-to-the-Center-of-the-Earth-Twenty-Thousand-Leagues-Under-the-Seas-by-Jules-Verne.pdf
    • http://loaminoo.linkpc.net/6097099098095098/World-Market-for-Hat-Forms-Bodies-Hoods-Plateaux-and-Manchons-Made-of-Felt-The-A-2007-Global-Trade-Perspective-by-Philip-M-Parker.pdf
    • http://loaminoo.linkpc.net/1091092091097095092/Economics-of-the-International-Coal-Trade-Why-Coal-Continues-to-Power-the-World-by-Lars-Schernikau.pdf
    • http://loaminoo.linkpc.net/2099093090098099/The-Center-Circle-Book-1-in-The-Center-Circle-Chronicles-by-Steve-Biddison.pdf
    • http://loaminoo.linkpc.net/4098096096091094/The-Slave-Trade-The-Story-of-the-Atlantic-Slave-Trade-1440-1870-by-Hugh-Thomas.pdf
    • http://loaminoo.linkpc.net/2095095094093095/Confederate-Odyssey-The-George-W-Wray-Jr-Civil-War-Collection-at-the-Atlanta-History-Center-by-Atlanta-History-Center.pdf
    • http://loaminoo.linkpc.net/1097092091099097/Far-and-Away-by-Sonja-Massie.pdf
    • http://loaminoo.linkpc.net/7092094092099090/Nil-Remembered-Nil-0-5-by-Lynne-Matson.pdf
    • http://loaminoo.linkpc.net/9097095098094/Works-of-Jules-Verne-Twenty-Thousand-Leagues-Under-the-Sea-A-Journey-to-the-Center-of-the-Earth-From-the-Earth-to-the-Moon-Round-the-Moon-Around-the-World-in-Eighty-Days-by-Jules-Verne.pdf