Malicious PDF — malware analysis report

Static analysis result for SHA-256 88176e282508db4d…

MALICIOUS

PDF

15.4 KB Created: 2019-05-02 02:10:45 +01:00 Authoring application: mPDF 5.7
MD5: 95085115517423485c31fff37fbf4cff SHA-1: 71843203781b4177000878381b6805ecd0d8b752 SHA-256: 88176e282508db4d105d2f0d0b0b59f35b1dab029ac678b6831c7c93ea917f07
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097094097093099/Distant-Desires-Distant-Desires-1-3-by-Cambria-Hebert.pdf
    • http://loaminoo.linkpc.net/2093093090/Avatar-The-Last-Airbender-Smoke-and-Shadow-Part-2-Smoke-and-Shadow-2-by-Gene-Luen-Yang.pdf
    • http://loaminoo.linkpc.net/3093090094092092/Smoke-and-Mirrors-Smoke-and-Mirrors-1-by-Lillian-T-MacGowan.pdf
    • http://loaminoo.linkpc.net/9097091099095099/de-Profundis-by-Eduardo-Acevedo.pdf
    • http://loaminoo.linkpc.net/2090095098096090/Memory-of-Fire-by-Eduardo-Galeano.pdf
    • http://loaminoo.linkpc.net/5090096099095092/Tomorrow-They-Will-Kiss-A-Novel-by-Eduardo-Santiago.pdf
    • http://loaminoo.linkpc.net/1091098090092091093/The-Polish-Boxer-by-Eduardo-Halfon.pdf
    • http://loaminoo.linkpc.net/1090091092094099/As-Mulheres-do-Meu-Pai-by-Jos-Eduardo-Agualusa.pdf
    • http://loaminoo.linkpc.net/4096098095095099/Faces-and-Masks-by-Eduardo-Galeano.pdf
    • http://loaminoo.linkpc.net/4096097090093098/Daughter-of-Smoke-and-Bone-Daughter-of-Smoke-amp-Bone-1-by-Laini-Taylor.pdf
    • http://loaminoo.linkpc.net/3091099094091096/The-Book-of-Chameleons-A-Novel-by-Jos-Eduardo-Agualusa.pdf
    • http://loaminoo.linkpc.net/1091091096094099091/EVANGELIUM-The-Prophecy-of-The-Astronauts-by-Eduardo-Barboza.pdf
    • http://loaminoo.linkpc.net/8094098098097/The-Price-of-Everything-Solving-the-Mystery-of-Why-We-Pay-What-We-Do-by-Eduardo-Porter.pdf
    • http://loaminoo.linkpc.net/3094098099090/Genesis-Memory-of-Fire-1-by-Eduardo-Galeano.pdf
    • http://loaminoo.linkpc.net/5097093092099093/The-Catastrophe-Aldebaran-1-2-by-Luiz-Eduardo-de-Oliveira-Leo-.pdf
    • http://loaminoo.linkpc.net/1093099093094094/Faces-and-Masks-Memory-of-Fire-2-by-Eduardo-Galeano.pdf
    • http://loaminoo.linkpc.net/2096092099092099/Pink-Ballerina-Our-Cyber-World-2-by-Eduardo-Suastegui.pdf
    • http://loaminoo.linkpc.net/5091091099098096/As-Baleas-de-Eduardo-Reinoso-by-Alfonso-Alvarez-Caccamo.pdf
    • http://loaminoo.linkpc.net/1091094097099095092/Artistic-Research-Being-There-Explorations-Into-the-Local-by-Eduardo-Abrantes.pdf
    • http://loaminoo.linkpc.net/7098094093095095/The-Argentine-Economy-Policy-Reform-for-Development-by-Eduardo-Conesa.pdf