Malicious PDF — malware analysis report

Static analysis result for SHA-256 86d0aeff194bb53e…

MALICIOUS

PDF

20.6 KB Created: 2019-04-30 17:18:55 +01:00 Authoring application: mPDF 5.7
MD5: dbce518e5cf35c5a3c0504c5281e4c0b SHA-1: ec79f8e30b9294f65d1157abae003ea1311aec13 SHA-256: 86d0aeff194bb53ecedbd1c8ee9552e2f8cc3ed174f998f05793a4369d926f20
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and contains a large number of external links, many of which are dynamically generated with numeric slugs. While the specific URLs extracted were labeled as benign, the sheer volume and structure suggest a malicious intent, likely for SEO spam or to redirect users to malicious sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5094097097099093/Wolf-Children-and-the-Problem-of-Human-Nature-With-the-Complete-Text-of-the-Wild-Boy-of-Aveyron-by-Lucien-Malson.pdf
    • http://loaminoo.linkpc.net/2093098090093093/Wild-Boy-of-Aveyron-by-Jean-Marc-Gaspard-Itard.pdf
    • http://loaminoo.linkpc.net/4096090094097/Wild-Boy-The-Real-Life-of-the-Savage-of-Aveyron-by-Mary-Losure.pdf
    • http://loaminoo.linkpc.net/4099094098099090/The-Nature-Principle-Human-Restoration-and-the-End-of-Nature-Deficit-Disorder-by-Richard-Louv.pdf
    • http://loaminoo.linkpc.net/3098091099097090/The-Geographical-History-of-America-Or-the-Relation-of-Human-Nature-to-the-Human-Mind-by-Gertrude-Stein.pdf
    • http://loaminoo.linkpc.net/6090098093092096/The-Human-Sciences-and-Philosophy-Cape-Editions-30-by-Lucien-Goldmann.pdf
    • http://loaminoo.linkpc.net/3099091091097095/No-Self-No-Problem-Awakening-to-Our-True-Nature-by-Anam-Thubten.pdf
    • http://loaminoo.linkpc.net/8091092099094094/An-Enquiry-Concerning-Human-Understanding-With-Hume-s-Abstract-of-a-Treatise-of-Human-Nature-and-a-Letter-from-a-Gentleman-to-His-Friend-in-Edinburgh-by-David-Hume.pdf
    • http://loaminoo.linkpc.net/6092097093090095/Number-Power-Problem-Solving-and-Test-Taking-Strategies-Student-Text-by-Ellen-Frechette.pdf
    • http://loaminoo.linkpc.net/8097098092095099/Human-All-Too-Human-Complete-Works-3-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/1090095091096098099/Genethics-Technological-Intervention-in-Human-Reproduction-as-a-Philosophical-Problem-by-Kurt-Bayertz.pdf
    • http://loaminoo.linkpc.net/5097096099095099/The-Art-of-War-Complete-Text-and-Commentaries-by-Sun-Tzu.pdf
    • http://loaminoo.linkpc.net/1090094095098092/The-Philokalia-the-Complete-Text-by-G-E-H-Palmer.pdf
    • http://loaminoo.linkpc.net/4093091099099093/Human-Nature-by-Jason-Halstead.pdf
    • http://loaminoo.linkpc.net/1094096094095098/Human-Nature-by-Alice-Anderson.pdf
    • http://loaminoo.linkpc.net/5097096099096092/The-Iliad-According-to-the-Text-of-Wolf-with-Notes-for-the-Use-of-Schools-and-Colleges-by-Homer.pdf
    • http://loaminoo.linkpc.net/2097092093091099/The-Philokalia-Volume-2-The-Complete-Text-by-G-E-H-Palmer.pdf
    • http://loaminoo.linkpc.net/8095092096091099/Strange-Tools-Art-and-Human-Nature-by-Alva-No-.pdf
    • http://loaminoo.linkpc.net/3093091094094090/Doctor-Who-Human-Nature-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/5096090098099099/The-Divine-Comedy-The-Complete-Text-by-Dante-Alighieri.pdf