Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ce5cab8f151ed55…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 01:57:59 +01:00 Authoring application: mPDF 5.7
MD5: 3f76f145a81dcddf712f5725f490efb8 SHA-1: 3eb6d67fb145491a839770a3d65ae24de89da6b3 SHA-256: 7ce5cab8f151ed55612e195d99cac0d6d7c8d57213546c3ff516ac14670604bd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. The primary heuristic indicates this is likely for SEO manipulation or to distribute further malicious content. While no scripts were extracted, the structure and link farm suggest a malicious intent to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8094091098093090/Sons-and-Lovers-1913-Novel-by-D-H-Lawrence-100-Best-Novels-of-the-20th-Century-Include-Women-in-Love-1920-Novel-By-D-H-Lawrence-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/1090093099090092098/THE-PLUMED-SERPENT-by-D-H-Lawrence-author-of-Sons-and-Lovers-The-Rainbow-Women-in-Love-and-Lady-Chatterley-s-Lover-Annotated-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/1091098099096092093/Sons-and-Lovers-1913-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/8094091098099096/Women-in-Love-20th-century-Classics-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/1090093098097094094/Lady-Chatterley-s-lover-The-Rainbow-Sons-and-lovers-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/9092092090094099/Sons-and-Lovers-1000-Copy-Limited-Edition-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/4093092094095093/The-Golden-Warrior-The-Life-and-Legend-of-Lawrence-of-Arabia-by-Lawrence-James.pdf
    • http://loaminoo.linkpc.net/3096098093099/Women-in-Love-Brangwen-Family-2-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/7092093091095095/Brahms-1913-by-J-Lawrence-Erb.pdf
    • http://loaminoo.linkpc.net/4092094093090098/By-the-El-Third-Avenue-and-Its-El-at-Mid-Century-by-Lawrence-Stelter.pdf
    • http://loaminoo.linkpc.net/2098090099091/American-Law-in-the-Twentieth-Century-by-Lawrence-M-Friedman.pdf
    • http://loaminoo.linkpc.net/1091092091096092097/The-Works-of-D-H-Lawrence-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/3091092096092097/D-H-Lawrence-and-Italy-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/5091092094099090/Always-the-Love-of-Someone-by-Huw-Lawrence.pdf
    • http://loaminoo.linkpc.net/1090096097097092097/Lawrence-Welk-s-Polka-Folio-Piano-amp-Piano-Accordion-by-Lawrence-Welk.pdf
    • http://loaminoo.linkpc.net/1090096097095095097/Wunnerful-Wunnerful-The-Autobiography-of-Lawrence-Welk-by-Lawrence-Welk.pdf
    • http://loaminoo.linkpc.net/4097094090092099/Sea-and-Sardinia-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/4090090099091096/Anatomic-by-Ali-Lawrence.pdf
    • http://loaminoo.linkpc.net/3092097096092098/Already-Gone-by-Jeremy-Lawrence.pdf
    • http://loaminoo.linkpc.net/1095090099099/What-We-Don-t-Know-About-Each-Other-by-Lawrence-Raab.pdf