Malicious PDF — malware analysis report

Static analysis result for SHA-256 8891f63133b72205…

MALICIOUS

PDF

16.0 KB Created: 2019-05-02 01:33:57 +01:00 Authoring application: mPDF 5.7
MD5: 0eaf3158c6df68e820a9765753876911 SHA-1: 51493729aa28e74847e3d16b7189eae411d7674c SHA-256: 8891f63133b722050f0a8812f2f804228153e86c21dec0710b67677bdc71295e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing of 'PDF_SEO_LINK_FARM' indicate a malicious intent to manipulate search engine results or redirect users to potentially harmful content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091094098093091096/Secret-Hudson-A-Finding-Nolan-Novel-2-by-K-S-Thomas.pdf
    • http://loaminoo.linkpc.net/5093095099093099/Kiera-Hudson-amp-The-Secret-Identity-Kiera-Hudson-Series-Three-4-by-Tim-O-39-Rourke.pdf
    • http://loaminoo.linkpc.net/7090099092095091/Finding-Figaro-by-Penny-Hudson.pdf
    • http://loaminoo.linkpc.net/4096092097091/Secret-of-the-Andes-by-Ann-Nolan-Clark.pdf
    • http://loaminoo.linkpc.net/1091094098092095091/The-Secret-Cardinal-Nolan-Kilkenny-Thriller-5-by-Tom-Grace.pdf
    • http://loaminoo.linkpc.net/9097091099097/Doctor-Hudson-s-Secret-Journal-by-Lloyd-C-Douglas.pdf
    • http://loaminoo.linkpc.net/6096098097098094/Hudson-Valley-Ruins-Forgotten-Landmarks-of-an-American-Landscape-by-Thomas-Rinaldi.pdf
    • http://loaminoo.linkpc.net/2092099094091095/Nolan-Trilogy-Box-Set-Under-Mr-Nolan-s-Bed-1-3-by-Selena-Kitt.pdf
    • http://loaminoo.linkpc.net/5095097093095091/Finding-Julien-Love-In-Secret-1-by-Genevieve-Wolfe.pdf
    • http://loaminoo.linkpc.net/3096095096090094/Spiritual-Secret-of-Hudson-Taylor-by-Howard-Taylor.pdf
    • http://loaminoo.linkpc.net/2098092098097095/Zen-in-the-Garden-Finding-Peace-and-Healing-Through-Nature-by-Tracy-J-Thomas.pdf
    • http://loaminoo.linkpc.net/5093095099097095/Kiera-Hudson-amp-The-Final-Push-Kiera-Hudson-Series-Three-Book-7-by-Tim-O-39-Rourke.pdf
    • http://loaminoo.linkpc.net/6099094090098096/The-Buddha-s-Way-of-Happiness-Healing-Sorrow-Transforming-Negative-Emotion-amp-Finding-Well-Being-in-the-Present-Moment-by-Thomas-Bien.pdf
    • http://loaminoo.linkpc.net/5093095099094092/Kiera-Hudson-amp-The-Origins-of-Cara-Kiera-Hudson-Series-Three-6-by-Tim-O-39-Rourke.pdf
    • http://loaminoo.linkpc.net/4092097092097092/Miracle-Man-Nolan-Ryan-The-Autobiography-by-Nolan-Ryan.pdf
    • http://loaminoo.linkpc.net/3096099091091094/Washington-s-Secret-War-by-Thomas-J-Fleming.pdf
    • http://loaminoo.linkpc.net/6097095093095092/The-Secret-Integration-by-Thomas-Pynchon.pdf
    • http://loaminoo.linkpc.net/3093092099098094/Every-Woman-Knows-a-Secret-by-Rosie-Thomas.pdf
    • http://loaminoo.linkpc.net/1099095091096/Secret-Societies-Thomas-Newton-1-by-William-Holden.pdf
    • http://loaminoo.linkpc.net/6090092099092/Gideon-s-Spies-The-Secret-History-of-the-Mossad-by-Gordon-Thomas.pdf