Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ae8a71f99aaf307…

MALICIOUS

PDF

16.6 KB Created: 2019-05-03 05:44:34 +01:00 Authoring application: mPDF 5.7
MD5: c39fd41504dcab56051b5b6560cd4d89 SHA-1: 3e33d9d5e4e0d055c5b65e9768a8019cad1a1ec3 SHA-256: 8ae8a71f99aaf307afb10ffe2c25663548f37acec8dfac56b07203dd11c20e1f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a multitude of external websites, likely for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097093095099/Towards-the-Promised-Land-Out-of-Jerusalem-3-by-H-B-Moore.pdf
    • http://loaminoo.linkpc.net/4097095090095093/Manchild-in-the-Promised-Land-by-Claude-Brown.pdf
    • http://loaminoo.linkpc.net/6095094097098097/Fatherland-or-Promised-Land-by-Jehuda-Reinharz.pdf
    • http://loaminoo.linkpc.net/2091090093094091/Day-of-Remembrance-The-Promised-Land-Vol-4-by-David-G-Woolley.pdf
    • http://loaminoo.linkpc.net/3099094098094/Manchild-in-the-Promised-Land-by-Claude-Brown.pdf
    • http://loaminoo.linkpc.net/1099099098097/Exile-in-the-Promised-Land-A-Memoir-by-Marcia-Freedman.pdf
    • http://loaminoo.linkpc.net/3097098096090097/Naked-in-the-Promised-Land-A-Memoir-by-Lillian-Faderman.pdf
    • http://loaminoo.linkpc.net/1091092098096098093/La-tierra-prometida-The-Promised-Land-by-Joachim-Masannek.pdf
    • http://loaminoo.linkpc.net/2091090092094096/Power-of-Deliverance-The-Promised-Land-2-by-David-G-Woolley.pdf
    • http://loaminoo.linkpc.net/2090094091097096/Naked-in-the-Promised-Land-A-Memoir-by-Lillian-Faderman.pdf
    • http://loaminoo.linkpc.net/4091094097091096/Oh-Promised-Land-Dabney-Family-Saga-1-by-James-H-Street.pdf
    • http://loaminoo.linkpc.net/3099098098097091/Compass-The-Journey-of-the-Soul-from-Egypt-to-the-Promised-Land-by-Penelope-V-Yorke.pdf
    • http://loaminoo.linkpc.net/5098097096094097/Jerusalem-amp-the-Holy-Land-by-Loti.pdf
    • http://loaminoo.linkpc.net/3096098091099099/The-Promised-Land-The-Great-Black-Migration-and-How-It-Changed-America-by-Nicholas-Lemann.pdf
    • http://loaminoo.linkpc.net/2093093096097091/The-Prophetess-Deborah-s-Story-Daughters-of-the-Promised-Land-2-by-Jill-Eileen-Smith.pdf
    • http://loaminoo.linkpc.net/5096091096092099/We-Are-Coming-Unafraid-The-Jewish-Legions-and-the-Promised-Land-in-the-First-World-War-by-Michael-Keren.pdf
    • http://loaminoo.linkpc.net/6097093092099091/Jerusalem-amp-the-Holy-Land-by-Fabrizio-Ardito.pdf
    • http://loaminoo.linkpc.net/1095092093094099/Redeeming-Grace-Ruth-s-Story-Daughters-of-the-Promised-Land-3-by-Jill-Eileen-Smith.pdf
    • http://loaminoo.linkpc.net/1092098093093097/Redneck-Boy-in-the-Promised-Land-The-Confessions-of-quot-Crazy-Cooter-quot-by-Ben-Jones.pdf
    • http://loaminoo.linkpc.net/3091097093091098/Promised-Promised-Series-1-by-Michelle-Turner.pdf