Malicious PDF — malware analysis report

Static analysis result for SHA-256 84589c2385e580c0…

MALICIOUS

PDF

19.5 KB Created: 2019-04-30 04:12:18 +01:00 Authoring application: mPDF 5.7
MD5: 4160ecb80b6599d0dddff294454f17b6 SHA-1: 21aa960655fe372ab23c253426b379ce04ee7376 SHA-256: 84589c2385e580c066df98999f65fb6509609369958a208dff578e3068fbb974
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to a dynamic DNS domain, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs appear benign, the sheer volume and the use of a dynamic DNS domain suggest a malicious intent, possibly for SEO poisoning or to host malicious content. No scripts were extracted, but the embedded URLs are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9893

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091095090099092096/The-19th-Hole-Architecture-of-the-Golf-Clubhouse-by-Richard-Diedrich.pdf
    • http://loaminoo.linkpc.net/6096092098096094/Hygiene-for-Management-19th-Edition-2017-by-Richard-A-Sprenger.pdf
    • http://loaminoo.linkpc.net/7099094090090097/The-Golf-Rules-Etiquette-by-Richard-E-Todd.pdf
    • http://loaminoo.linkpc.net/2091098096094/A-Hole-in-the-World-An-American-Boyhood-by-Richard-Rhodes.pdf
    • http://loaminoo.linkpc.net/7099094090091098/GOLF-The-Best-Instruction-Book-Ever-by-Golf-Magazine.pdf
    • http://loaminoo.linkpc.net/4096095091095096/The-Art-and-Architecture-of-Islamic-Cairo-by-Richard-Yeomans.pdf
    • http://loaminoo.linkpc.net/1090091096093096/The-Hole-in-Our-Gospel-What-Does-God-Expect-of-Us-the-Answer-That-Changed-My-Life-and-Might-Just-Change-the-World-by-Richard-Stearns.pdf
    • http://loaminoo.linkpc.net/1091095092098098098/The-Complete-Architecture-of-Adler-Sullivan-by-Richard-Nickel.pdf
    • http://loaminoo.linkpc.net/9093098090095098/The-Cosmic-Web-Mysterious-Architecture-of-the-Universe-by-J-Richard-Gott-III.pdf
    • http://loaminoo.linkpc.net/1092094095095091/A-Black-Hole-Is-Not-a-Hole-by-Carolyn-Cinami-Decristofano.pdf
    • http://loaminoo.linkpc.net/6097093091096092/GOLF-ETIQUETTE-The-20-Must-Know-Rules-of-Golf-Etiquette-by-Confident-Golfer.pdf
    • http://loaminoo.linkpc.net/6090093093095092/The-Architecture-of-Space-Memorandum-on-Architectural-Policy-1997-2000-Die-Architektur-Des-Raumes-Bericht-Zur-Architekturpolitik-1997-2000-L-Architecture-de-L-Espace-Note-Sur-La-Politique-En-Matiere-D-Architecture-1997-2000-La-Arquitectura-del-by-Oscar-Van-Alphen.pdf
    • http://loaminoo.linkpc.net/6095094095095090/Architecture-Lumiere-Et-Espace-Architecture-Light-And-Space-With-DVD-by-Michel-Lorand.pdf
    • http://loaminoo.linkpc.net/1092094094097096/Henry-and-the-Clubhouse-by-Beverly-Cleary.pdf
    • http://loaminoo.linkpc.net/3099098097090090/Born-to-Ride---A-Clubhouse-Collection-by-Kasey-Millstead.pdf
    • http://loaminoo.linkpc.net/1097097096091090/Servicing-Black-Thugs-The-Playa-The-Straight-Guy-Clubhouse-Book-7-by-Marcus-Greene.pdf
    • http://loaminoo.linkpc.net/1092092096093097/Day-After-The-19th-Year-2-by-Emi-Gayle.pdf
    • http://loaminoo.linkpc.net/1091095090099095098/For-Pet-s-Sake-Do-Something-Book-One-by-Monica-Diedrich.pdf
    • http://loaminoo.linkpc.net/9095095091091097/Panorama-Of-The-19th-Century-by-Dolf-Sternberger.pdf
    • http://loaminoo.linkpc.net/1091095091090091097/The-Languages-Of-West-Africa-by-Diedrich-Westermann.pdf