Malicious PDF — malware analysis report

Static analysis result for SHA-256 856742c0b4711f78…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 05:22:58 +01:00 Authoring application: mPDF 5.7
MD5: 476f4aa0ddc92b8394a6a57c9c22cd1f SHA-1: 88d6404d037195e01a6f54f9af77630929673785 SHA-256: 856742c0b4711f784975160b47c42f8272cb3ba4d95accd1cfc0d3dd0abcf55b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a link farm or SEO manipulation attempt. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. The document body is heavily obfuscated and unreadable, preventing further analysis of its specific intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9811

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4090098090096096/The-Marginal-Safari-Scouting-the-Edge-of-South-Africa-by-Justin-Fox.pdf
    • http://loaminoo.linkpc.net/1091092099096098096/Travel-in-South-Africa-by-South-Africa-Railways-and-Harbou-Board.pdf
    • http://loaminoo.linkpc.net/1098099091097099/A-Single-Swallow-Following-An-Epic-Journey-From-South-Africa-To-South-Wales-by-Horatio-Clare.pdf
    • http://loaminoo.linkpc.net/4091097099097092/Africa-on-Six-Wheels-A-Semester-on-Safari-by-Betty-Levitov.pdf
    • http://loaminoo.linkpc.net/1090097090096093090/Southern-Africa-Safari-Companion-by-Diana-Lerche.pdf
    • http://loaminoo.linkpc.net/5094090091094099/China-Safari-On-the-Trail-of-Beijing-s-Expansion-in-Africa-by-Serge-Michel.pdf
    • http://loaminoo.linkpc.net/4098090095096090/33-A-Gay-Love-Story-by-Justin-South.pdf
    • http://loaminoo.linkpc.net/4095097091095093/Alex-amp-Drew-by-Justin-South.pdf
    • http://loaminoo.linkpc.net/9091095093096094/Traumatic-Stress-in-South-Africa-by-Debra-Kaminer.pdf
    • http://loaminoo.linkpc.net/5090099090091096/No-Turning-Back-A-Novel-of-South-Africa-by-Beverley-Naidoo.pdf
    • http://loaminoo.linkpc.net/5094098090096098/Civil-Procedure-in-South-Africa-by-Roshana-Kelbrick.pdf
    • http://loaminoo.linkpc.net/4093098090093091/Cry-the-Beloved-Country-A-Novel-of-South-Africa-by-Edward-Callan.pdf
    • http://loaminoo.linkpc.net/1099097096092096/A-Rumour-of-Spring-South-Africa-After-20-Years-of-Democracy-by-Max-Du-Preez.pdf
    • http://loaminoo.linkpc.net/5097091092099/The-Road-to-Home-South-Africa-Series-1-by-Vanessa-Del-Fabbro.pdf
    • http://loaminoo.linkpc.net/4093096099098099/We-Make-Freedom-Women-in-South-Africa-by-Beata-Lipman.pdf
    • http://loaminoo.linkpc.net/2093091090091/Move-Your-Shadow-South-Africa-Black-and-White-by-Joseph-Lelyveld.pdf
    • http://loaminoo.linkpc.net/1091091090092092090/Trauma-Memory-and-Narrative-in-South-Africa-Interviews-by-Ewald-Mengel.pdf
    • http://loaminoo.linkpc.net/7092092096098094/Theory-from-the-South-Or-How-Euro-America-Is-Evolving-Toward-Africa-by-Jean-Comaroff.pdf
    • http://loaminoo.linkpc.net/1091099095093094091/Profiling-Serial-Killers-and-other-Crimes-in-South-Africa-by-Micki-Pistorius.pdf
    • http://loaminoo.linkpc.net/8093097095099093/The-South-Africa-Reader-History-Culture-Politics-by-Clifton-Crais.pdf