Malicious PDF — malware analysis report

Static analysis result for SHA-256 7862d85ff37d59cf…

MALICIOUS

PDF

23.3 KB Created: 2019-05-01 18:28:34 +01:00 Authoring application: mPDF 5.7
MD5: 38f18bff0df1b210005394586b7f27cc SHA-1: 090052894da49883ad2b5b5202bff9dee5f77e0e SHA-256: 7862d85ff37d59cf12f31613be5fb3cf01de067dafaa018e2505a519a326ad20
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to harmful sites. No scripts were extracted, but the presence of embedded links points to a T1059.007 (JavaScript) technique, likely used to facilitate the link redirection. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5090098095098090/Taiga-s-True-Views-The-Language-of-Landscape-Painting-in-Eighteenth-Century-Japan-by-Melinda-Takeuchi.pdf
    • http://loaminoo.linkpc.net/3096095093096097/Unwise-Passions-A-True-Story-of-a-Remarkable-Woman---and-the-First-Great-Scandal-of-Eighteenth-Century-America-by-Alan-Pell-Crawford.pdf
    • http://loaminoo.linkpc.net/6095091096095094/Escaping-Japan-Reflections-on-Estrangement-and-Exile-in-the-Twenty-First-Century-Japan-Anthropology-Workshop-Series-by-Blai-Guarn-.pdf
    • http://loaminoo.linkpc.net/7096096090091098/Chinese-Landscape-Painting-Techniques-for-Watercolor-by-Lian-Quan-Zhen.pdf
    • http://loaminoo.linkpc.net/1095092096097/Nature-and-Culture-American-Landscape-and-Painting-1825-1875-by-Barbara-Novak.pdf
    • http://loaminoo.linkpc.net/1092092098097095/The-Programming-Language-Landscape-by-Henry-F-Ledgard.pdf
    • http://loaminoo.linkpc.net/1091094097093097092/The-Global-Eighteenth-Century-by-Felicity-Nussbaum.pdf
    • http://loaminoo.linkpc.net/4099097092097091/Tuning-Containing-The-Perfection-Of-Eighteenth-Century-Temperament-The-Lost-Art-Of-Nineteenth-Century-Temperament-And-The-Science-Of-Equal-Temperament-Complete-With-Instructions-For-Aural-And-Electronic-Tuning-by-Owen-H-Jorgensen.pdf
    • http://loaminoo.linkpc.net/9094090091096093/Eighteenth-Century-British-Midwifery-Part-II-by-Pam-Lieske.pdf
    • http://loaminoo.linkpc.net/5092093093098097/Lord-Hervey-Eighteenth-Century-Courtier-by-Halsband.pdf
    • http://loaminoo.linkpc.net/6093098093093091/Diocese-of-Killaloe-in-the-eighteenth-century-by-Ignatius-Murphy.pdf
    • http://loaminoo.linkpc.net/4091095097097097/De-Colores-Means-All-of-Us-Latina-Views-for-a-Multi-Colored-Century-by-Elizabeth-Mart-nez.pdf
    • http://loaminoo.linkpc.net/1090097098094093091/Modes-amp-Manners-From-the-Middle-Ages-to-the-End-of-the-Eighteenth-Century-by-Max-Von-Boehn.pdf
    • http://loaminoo.linkpc.net/6097094090092094/The-Libertine-The-Art-of-Love-in-Eighteenth-Century-France-by-Michel-Delon.pdf
    • http://loaminoo.linkpc.net/1090095097099099091/Nightwalkers-Prostitute-Narratives-from-the-Eighteenth-Century-by-Laura-J-Rosenthal.pdf
    • http://loaminoo.linkpc.net/1091091099095091095/John-Law-A-Scottish-Adventurer-in-the-Eighteenth-Century-by-James-Buchan.pdf
    • http://loaminoo.linkpc.net/5099095099093098/Eighteenth-Century-Britain-1688-1783-by-Jeremy-Black.pdf
    • http://loaminoo.linkpc.net/5096096098096096/Dangerous-Liaisons-Fashion-and-Furniture-in-the-Eighteenth-Century-by-Harold-Koda.pdf
    • http://loaminoo.linkpc.net/1095090098092091/The-Poor-of-Eighteenth-Century-France-1750-1789-by-Olwen-H-Hufton.pdf
    • http://loaminoo.linkpc.net/1091091094095099092/Transformations-of-the-German-Novel--Simplicissimus--In-Eighteenth-Century-Adaptations-by-Monique-Rinere.pdf