Malicious PDF — malware analysis report

Static analysis result for SHA-256 8607adf09019c9fa…

MALICIOUS

PDF

14.7 KB Created: 2019-04-30 04:06:15 +01:00 Authoring application: mPDF 5.7
MD5: 4e1ecf6d7d410715ca1b71de5ff4df06 SHA-1: f2337df9096da276ff15a390e7820d07060d7d16 SHA-256: 8607adf09019c9fa9484748ea1f6c773ee887611e22847e3e523cdad13a32aa7
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' indicate a suspicious pattern. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted, but the structure suggests a potential initial access vector via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9096099095092095/Silver-Lining-The-Guardian-of-Man-2-5-by-Melissa-A-Smith.pdf
    • http://loaminoo.linkpc.net/6091090091099093/Silver-Lining-Silver-Cove-1-by-Jill-Sanders.pdf
    • http://loaminoo.linkpc.net/4093096091092094/Silver-Lining-by-E-J-Shortall.pdf
    • http://loaminoo.linkpc.net/9096099097091090/The-Silver-Lining-by-Rohini-Vij.pdf
    • http://loaminoo.linkpc.net/9096099094092099/Silver-Lining-by-Christiane-Heggan.pdf
    • http://loaminoo.linkpc.net/9096099096093095/Silver-Lining-by-Wendy-Soliman.pdf
    • http://loaminoo.linkpc.net/1092090093097096/Silver-Lining-by-Maggie-Osborne.pdf
    • http://loaminoo.linkpc.net/9096099096094094/Silver-Lining-by-Charles-Cohen.pdf
    • http://loaminoo.linkpc.net/9096099096094096/A-Silver-Lining-by-Christine-Murray.pdf
    • http://loaminoo.linkpc.net/9096099096099095/silver-lining-by-Gemma-Robson.pdf
    • http://loaminoo.linkpc.net/9096099093095093/Look-for-the-Silver-Lining-by-June-Francis.pdf
    • http://loaminoo.linkpc.net/2090090094098094/Silver-Lining-by-Godwin-Iheanacho.pdf
    • http://loaminoo.linkpc.net/9096099093095095/Searching-for-a-Silver-Lining-by-Miranda-Dickinson.pdf
    • http://loaminoo.linkpc.net/9096099094092095/A-Silver-Lining-Hearts-of-Gold-3-by-Catrin-Collier.pdf
    • http://loaminoo.linkpc.net/9096099097091092/The-Silver-Lining-The-Benefits-of-Natural-Disasters-by-Seth-R-Reice.pdf
    • http://loaminoo.linkpc.net/2092096092092/Every-Silver-Lining-Has-a-Cloud-Relapse-and-the-Symptoms-of-Sobriety-by-Scott-Stevens.pdf
    • http://loaminoo.linkpc.net/1095091091096097/Death-by-Silver-by-Melissa-Scott.pdf
    • http://loaminoo.linkpc.net/1090094094098093099/The-Melissa-Rauch-Handbook---Everything-You-Need-to-Know-about-Melissa-Rauch-by-Emily-Smith.pdf
    • http://loaminoo.linkpc.net/1097097092098098/An-Autumn-Dream-Silver-Moon-Saga-1-5-by-Melissa-Giorgio.pdf
    • http://loaminoo.linkpc.net/1098099097092/Death-by-Silver-Julian-Lynes-and-Ned-Mathey-1-by-Melissa-Scott.pdf