Malicious PDF — malware analysis report

Static analysis result for SHA-256 78dd4cd58ebee857…

MALICIOUS

PDF

16.8 KB Created: 2019-04-30 04:28:47 +01:00 Authoring application: mPDF 5.7
MD5: 0cf51407e428fa27dcbc1a4fc1659b04 SHA-1: cb99cd61814fb8c10d9f22e851e14bcb48da43b3 SHA-256: 78dd4cd58ebee8576771b6e9300be6fe75608394925d3bb2cf6a81fd8dda0a40
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, suggesting a potential SEO manipulation or content hosting scheme. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the structure and URL distribution point towards a malicious intent, possibly to redirect users to harmful sites or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4090093098094/Slam-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/2097093092094099/How-To-Be-Good-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1091096095094092099/How-to-be-Good-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/4091093091091092/Not-A-Star-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/2096096090098097/How-to-Be-Good-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/7091096097094093/Everyone-s-Reading-Bastard-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/7090099094095/High-Fidelity-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/4096098094090096/Fever-Pitch-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/3092094095096/High-Fidelity-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/8091099094094096/Alta-fidelidade-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/3091094090096093/Not-a-Star-and-Otherwise-Pandemonium-Stories-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/3092095096096099/Not-a-Star-and-Otherwise-Pandemonium-Stories-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1091090099096090093/Weniger-reden-und-fter-mal-in-die-Badewanne---Mein-Leben-als-Leser-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/2097091094099099/Books-Movies-Rhythm-Blues-Twenty-Years-of-Writing-About-Film-Music-and-Books-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1096091090099093/Kyle-s-New-Stepbrother-II-Long-Hot-Summer-Nick-and-Kyle-Book-2-by-Brad-Vance.pdf
    • http://loaminoo.linkpc.net/1091096099098092097/Oxford-Advanced-Learner-s-Dictionary-by-A-S-Hornby.pdf
    • http://loaminoo.linkpc.net/7095097091094099/Toronto-and-the-Maple-Leafs-A-City-and-Its-Team-by-Lance-Hornby.pdf
    • http://loaminoo.linkpc.net/2098095094096099/The-Secret-Life-of-the-Love-Song-and-The-Flesh-Made-Word-Two-Lectures-by-Nick-Cave-by-Nick-Cave.pdf
    • http://loaminoo.linkpc.net/9097094098093096/Nick-and-Tesla-s-Special-Effects-Spectacular-A-Mystery-with-Animatronics-Alien-Makeup-Camera-Gear-and-Other-Movie-Magic-You-Can-Make-Yourself-Nick-and-Tesla-5-by-Bob-Pflugfelder.pdf
    • http://loaminoo.linkpc.net/5099096095092/A-Long-Long-Time-Ago-and-Essentially-True-by-Brigid-Pasulka.pdf