Malicious PDF — malware analysis report

Static analysis result for SHA-256 8071de0b278cc691…

MALICIOUS

PDF

17.2 KB Created: 2019-05-01 17:08:18 +01:00 Authoring application: mPDF 5.7
MD5: 30760bb704a024ea8fe85fde74d3045f SHA-1: ed957b8360d593155b6c684461a5db1bd5d1639d SHA-256: 8071de0b278cc6911518e787f06564b7c6d5d5607e62f4bf4434f919ff22d2a5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF was flagged by a machine learning classifier and contains a heuristic indicating a large number of external links, many with numeric slugs. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a link farm or SEO spam tactic, potentially leading to malicious content or phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093090092099096/New-Fashion-Figure-Templates-Over-250-Templates-by-Patrick-John-Ireland.pdf
    • http://loaminoo.linkpc.net/4098092099094096/The-Fairy-Artist-s-Figure-Drawing-Bible-Ready-To-Draw-Templates-and-Step-By-Step-Rendering-Techniques-by-Linda-Ravenscroft.pdf
    • http://loaminoo.linkpc.net/9093097097097090/Rjs-Templates-for-Rails-by-Cody-Fauser.pdf
    • http://loaminoo.linkpc.net/8095094094093091/Figure-Drawing-for-Fashion-Design-by-Elisabetta-Drudi.pdf
    • http://loaminoo.linkpc.net/7092092090097/Patrick-Son-of-Ireland-by-Stephen-R-Lawhead.pdf
    • http://loaminoo.linkpc.net/6095099096099095/Emerald-Germs-of-Ireland-by-Patrick-McCabe.pdf
    • http://loaminoo.linkpc.net/8095094093098096/The-Human-Figure-by-John-H-Vanderpoel.pdf
    • http://loaminoo.linkpc.net/1098094092095094/The-Figure-in-the-Shadows-Lewis-Barnavelt-2-by-John-Bellairs.pdf
    • http://loaminoo.linkpc.net/6099090094093097/A-Figure-of-Speech-A-Festschrift-for-John-Laver-by-Ann-Taket-Barter-Godfrey.pdf
    • http://loaminoo.linkpc.net/1091096096097094099/Fashion-Zeitgeist-Trends-and-Cycles-in-the-Fashion-System-by-Barbara-Vinken.pdf
    • http://loaminoo.linkpc.net/4093092094094094/Crimes-of-Fashion-Three-Women-One-Fashion-Empire-Six-Claws-by-Jonathan-Soroff.pdf
    • http://loaminoo.linkpc.net/8092091095097090/Explaining-Northern-Ireland-by-John-McGarry.pdf
    • http://loaminoo.linkpc.net/6092090095094/John-Patrick-Norman-McHennessy-The-Boy-Who-Was-Always-Late-by-John-Burningham.pdf
    • http://loaminoo.linkpc.net/1091099097099092090/A-New-History-of-Ireland-Volume-II-Medieval-Ireland-1169-1534-by-Art-Cosgrove.pdf
    • http://loaminoo.linkpc.net/1090096097095093099/Coastal-Rail-Termini-of-Britain-and-Ireland-by-John-Hillmer.pdf
    • http://loaminoo.linkpc.net/1090093097093091098/50s-Fashion-Vintage-Fashion-and-Beauty-Ads-by-Jim-Heimann.pdf
    • http://loaminoo.linkpc.net/6090092098098092/Humbert-A-French-General-In-Rebel-Ireland-1798-by-John-Cooney.pdf
    • http://loaminoo.linkpc.net/3093090097098093/Display-of-Power-How-Fubu-Changed-a-World-of-Fashion-Branding-and-Lifestyle-by-Daymond-John.pdf
    • http://loaminoo.linkpc.net/5090091097099/Two-Walls-and-a-Roof-Ireland-Born-America-Bound-by-John-Michael-Cahill.pdf
    • http://loaminoo.linkpc.net/3092090096098096/Northern-Ireland-Can-Sean-and-John-Live-in-Peace-by-Carol-Daugherty-Rasnic.pdf