Malicious PDF — malware analysis report

Static analysis result for SHA-256 889566fe892b30ce…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 17:40:00 +01:00 Authoring application: mPDF 5.7
MD5: 05c539cd3ba399f9343cad966d3c0903 SHA-1: 80c8d3c2bb7ede24071a6a7ae4ce9583eb2fbda8 SHA-256: 889566fe892b30ce1b3d5685e1072c8756e4f456c8657f9a948b05256a156b53
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, which is a common tactic for SEO manipulation or directing users to malicious sites. While the document body is unreadable, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests the intent is to drive traffic to external resources. The ML classifier also flagged the PDF as malicious, supporting this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1094095099095091/A-Turn-of-Light-Night-s-Edge-1-by-Julie-E-Czerneda.pdf
    • http://loaminoo.linkpc.net/2090093094096090/Stardust-by-Julie-E-Czerneda.pdf
    • http://loaminoo.linkpc.net/1096090094097098/Beholder-s-Eye-Web-Shifters-1-by-Julie-E-Czerneda.pdf
    • http://loaminoo.linkpc.net/2097093097097090/Survival-Species-Imperative-1-by-Julie-E-Czerneda.pdf
    • http://loaminoo.linkpc.net/1091095092091098096/Mythspring-From-the-Myths-and-Lyrics-of-Canada-by-Julie-E-Czerneda.pdf
    • http://loaminoo.linkpc.net/2093091091093098/Ties-of-Power-Trade-Pact-Universe-2-by-Julie-E-Czerneda.pdf
    • http://loaminoo.linkpc.net/1094096096099093/A-Thousand-Words-for-Stranger-Trade-Pact-Universe-1-by-Julie-E-Czerneda.pdf
    • http://loaminoo.linkpc.net/6091095091099092/Edge-of-Darkness-Edge-of-Light-by-R-C-Scriven.pdf
    • http://loaminoo.linkpc.net/3094098093091099/Straddling-the-Edge-Against-the-Wall-3-by-Julie-Prestsater.pdf
    • http://loaminoo.linkpc.net/3091095097099091/All-the-Light-There-Is-The-Healing-Edge-3-by-Anise-Eden.pdf
    • http://loaminoo.linkpc.net/2097097093090092/The-Edge-of-Light-At-Home-in-Beldon-Grove-1-by-Ann-Shorey.pdf
    • http://loaminoo.linkpc.net/4094097092096095/First-Light-The-Search-for-the-Edge-of-the-Universe-by-Richard-Preston.pdf
    • http://loaminoo.linkpc.net/1097095096094092/The-Edge-of-the-Light-Whidbey-Island-Saga-4-by-Elizabeth-George.pdf
    • http://loaminoo.linkpc.net/4094099091090096/Turn-Left-at-Orion-A-Hundred-Night-Sky-Objects-to-See-in-a-Small-Telescope---And-How-to-Find-Them-by-Guy-Consolmagno.pdf
    • http://loaminoo.linkpc.net/4092092090094090/The-Battle-Between-Light-and-Dark-Book-1-The-Prophecy-of-the-Seventh-Elizabeth-1-by-Jarrod-L-Edge.pdf
    • http://loaminoo.linkpc.net/1090095098093093092/Pieces-of-Light-Dinah-Harris-Mysteries-3-by-Julie-Cave.pdf
    • http://loaminoo.linkpc.net/2094097099095090/Rapture-s-Edge-Night-Prowler-3-by-J-T-Geissinger.pdf
    • http://loaminoo.linkpc.net/8099097096/The-Ragged-Edge-of-Night-by-Olivia-Hawker.pdf
    • http://loaminoo.linkpc.net/1099096092098097/Shadow-s-Edge-Night-Prowler-1-by-J-T-Geissinger.pdf
    • http://loaminoo.linkpc.net/1091096090099/Edge-of-Oblivion-Night-Prowler-2-by-J-T-Geissinger.pdf