Malicious PDF — malware analysis report

Static analysis result for SHA-256 817761ea6403cce8…

MALICIOUS

PDF

15.7 KB Created: 2019-05-01 17:41:30 +01:00 Authoring application: mPDF 5.7
MD5: 5d9314b311cd37213519013852784152 SHA-1: 6e34acfb50bda2a535caebcadb8b11f3d4b853ab SHA-256: 817761ea6403cce8c9faf3cc07cf0d6751b7192a7e72514566df6f49f898c5ae
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' suggest a malicious intent to manipulate search engine results or to host potentially harmful content. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096099098095093/Keeper-of-the-Lost-Souls-Keeper-Witches-1-by-Kristy-Centeno.pdf
    • http://loaminoo.linkpc.net/2097095093095/Keeper-of-the-Lost-Cities-Keeper-of-the-Lost-Cities-1-by-Shannon-Messenger.pdf
    • http://loaminoo.linkpc.net/4093099097096095/Marcus-The-Keeper-of-Lights-The-Keeper-Series-Book-1-by-John-Vice.pdf
    • http://loaminoo.linkpc.net/4091090097097097/Keeper-Vol-2-The-Morphid-Chronicles-Keeper-2-by-Ingrid-Seymour.pdf
    • http://loaminoo.linkpc.net/2097097099095091/The-Keeper-of-the-Wolf-Clan-Keeper-of-Wolves-1-by-Red-Phoenix.pdf
    • http://loaminoo.linkpc.net/3099091094098099/The-Keeper-s-Quest-The-Keeper-s-Saga-2-by-Kelly-Nelson.pdf
    • http://loaminoo.linkpc.net/1093094097094095/Summon-the-Keeper-Keeper-Chronicles-1-by-Tanya-Huff.pdf
    • http://loaminoo.linkpc.net/5091093097091/Keeper-Keeper-Series-1-by-Robyn-Roze.pdf
    • http://loaminoo.linkpc.net/4097098097091097/Deliverance-by-Kristy-Centeno.pdf
    • http://loaminoo.linkpc.net/7092098094096090/The-Reformed-Librarie-Keeper-Or-Two-Copies-of-Letters-Concerning-the-Place-and-Office-of-a-Librarie-Keeper-by-John-Dury.pdf
    • http://loaminoo.linkpc.net/2092096095093092/The-Keeper-Keeper-1-by-Sarah-Langan.pdf
    • http://loaminoo.linkpc.net/7096092091094/Neverseen-Keeper-of-the-Lost-Cities-4-by-Shannon-Messenger.pdf
    • http://loaminoo.linkpc.net/3092091093099092/Untitled-Keeper-of-Lost-Cities-8-by-Shannon-Messenger.pdf
    • http://loaminoo.linkpc.net/4097090099095/The-Keeper-of-Lost-Causes-Department-Q-1-by-Jussi-Adler-Olsen.pdf
    • http://loaminoo.linkpc.net/3092091093098096/Untitled-Keeper-of-Lost-Cities-9-by-Shannon-Messenger.pdf
    • http://loaminoo.linkpc.net/2092090097090097/Lost-Empire-The-Legend-of-the-Gate-Keeper-3-by-Jeff-Gunzel.pdf
    • http://loaminoo.linkpc.net/1090097093097091090/The-Keeper-of-Lost-Things-The-feel-good-novel-of-the-year-by-Ruth-Hogan.pdf
    • http://loaminoo.linkpc.net/1098097099095090/The-Dream-Keeper-Dream-Keeper-Chronicles-1-by-Mikey-Brooks.pdf
    • http://loaminoo.linkpc.net/4097091099090090/The-Secret-Keeper-Holds-On-The-Secret-Keeper-4-by-Brea-Brown.pdf
    • http://loaminoo.linkpc.net/4091099094091093/Mother-Keeper-Vol-1-Mother-Keeper-1-by-Kairi-Sorano.pdf