Malicious PDF — malware analysis report

Static analysis result for SHA-256 80c5af1abcf9da87…

MALICIOUS

PDF

18.1 KB Created: 2019-04-30 04:58:53 +01:00 Authoring application: mPDF 5.7
MD5: 13ac4a78553e440364b1163cb6bfb3c9 SHA-1: 42d4a1eb8cd06c68e38697e315b6be73063430a1 SHA-256: 80c5af1abcf9da87e0efc408aec138601012e748e05aad351c8b7550ecd2bb29
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. ClamAV detected this file as Pdf.Dropper.Agent-7178175-0, and an ML classifier also flagged it as malicious. The embedded URLs, while currently marked as benign, are part of a link farm structure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7178175-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7178175-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9095092090095/Raised-by-Hand-Lifted-by-the-Tides-A-Southern-Child-s-Memoir-by-Willett-Thomas.pdf
    • http://loaminoo.linkpc.net/1098095094096091/A-Lucky-Child-A-Memoir-of-Surviving-Auschwitz-as-a-Young-Boy-by-Thomas-Buergenthal.pdf
    • http://loaminoo.linkpc.net/3094097098096091/Raised-Country-Southern-Bred-2-by-Willow-Brooke.pdf
    • http://loaminoo.linkpc.net/3097098091097098/The-Women-Who-Raised-Me-A-Memoir-by-Victoria-Rowell.pdf
    • http://loaminoo.linkpc.net/2091095090093095/The-Boy-Who-Was-Raised-as-a-Dog-and-Other-Stories-from-a-Child-Psychiatrist-s-Notebook-by-Bruce-D-Perry.pdf
    • http://loaminoo.linkpc.net/1090096097099090/The-Girl-With-No-Name-The-Incredible-True-Story-of-a-Child-Raised-by-Monkeys-by-Marina-Chapman.pdf
    • http://loaminoo.linkpc.net/2099097096090091/Don-t-Let-My-Mama-Read-This-A-Southern-Fried-Memoir-by-Hadjii.pdf
    • http://loaminoo.linkpc.net/1091097095095098093/The-Hand-I-Played-A-Poker-Memoir-by-David-Spanier.pdf
    • http://loaminoo.linkpc.net/1098094099099090/The-Big-Field-A-Child-s-Year-Under-the-Southern-Cross-by-Anne-Morddel.pdf
    • http://loaminoo.linkpc.net/1091095099097095095/Frauen-die-den-Faden-in-der-Hand-halten-by-Thomas-Blisniewski.pdf
    • http://loaminoo.linkpc.net/7093091093091098/The-Hand-of-Ethelberta-A-Comedy-in-Chapters-by-Thomas-Hardy.pdf
    • http://loaminoo.linkpc.net/2095093090096096/Hannah-s-Child-A-Theologian-s-Memoir-by-Stanley-Hauerwas.pdf
    • http://loaminoo.linkpc.net/4093096094096094/Mulberry-Child-A-Memoir-of-China-by-Jian-Ping.pdf
    • http://loaminoo.linkpc.net/9099096090093095/Hand-of-Fire-The-Master-of-the-Tane-Book-1-by-Thomas-Rath.pdf
    • http://loaminoo.linkpc.net/9096090097092092/Mindele-s-Journey-Memoir-of-a-Hidden-Child-of-the-Holocaust-by-Mariette-Bermowitz.pdf
    • http://loaminoo.linkpc.net/5092097091091090/Love-Child-A-Memoir-of-Family-Lost-and-Found-by-Allegra-Huston.pdf
    • http://loaminoo.linkpc.net/1092094094090097/Angel-Eyes-A-Collective-Memoir-of-Child-Sexual-Abuse-by-Katandra-Jackson-Nunnally.pdf
    • http://loaminoo.linkpc.net/2094091099092097/This-Child-Will-Be-Great-Memoir-of-a-Remarkable-Life-by-Africa-s-First-Woman-President-by-Ellen-Johnson-Sirleaf.pdf
    • http://loaminoo.linkpc.net/2093092094098090/The-Lifted-Veil-by-George-Eliot.pdf
    • http://loaminoo.linkpc.net/3094090098093094/A-Good-Thing-2-If-I-Be-Lifted-Up-by-She-Nell.pdf