Malicious PDF — malware analysis report

Static analysis result for SHA-256 92ee5af852e44de0…

MALICIOUS

PDF

18.4 KB Created: 2019-04-30 03:19:40 +01:00 Authoring application: mPDF 5.7 First seen: 2020-12-28
MD5: fb945ed2bc6da2427a2eed0aeddf5b53 SHA-1: 19157de419c94733794eab56cd7932238c0a0842 SHA-256: 92ee5af852e44de00847f711ee1785071c339a06a1a9f56d32f9072fc6fd2432
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, masquerading as document content. The heuristic 'PDF_SEO_LINK_FARM' indicates this is a link farm, likely intended to drive traffic or distribute further malicious content. While the URLs themselves are marked as benign, the sheer volume and nature of the links suggest a malicious intent to mislead the user. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097092093090090/The-Wall-Street-Zen-Golf-Club-by-William-S-Spilman-Jr-.pdf In PDF document text
    • http://loaminoo.linkpc.net/6095095091098098/Molly-s-Game-From-Hollywood-s-Elite-to-Wall-Street-s-Billionaire-Boys-Club-My-High-Stakes-Adventure-in-the-World-of-Underground-Poker-by-Molly-Bloom.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090091096091095099/When-Washington-Shut-Down-Wall-Street-The-Great-Financial-Crisis-of-1914-and-the-Origins-of-America-s-Monetary-Supremacy-by-William-L-Silber.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7091094096094/The-Wolf-of-Wall-Street-The-Wolf-of-Wall-Street-1-by-Jordan-Belfort.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2091097098091091/The-Golf-Widows-Club-by-Emily-Harvale.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4098099096099098/Your-15th-Club-The-Inner-Secret-to-Great-Golf-by-Bob-Rotella.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3094098090094091/King-of-Wall-Street-by-Louise-Bay.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8090095090/Hot-Asset-21-Wall-Street-1-by-Lauren-Layne.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1095094097095091/Wall-Street-and-The-Rise-Of-Hitler-by-Antony-C-Sutton.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090097096099096/A-Random-Walk-Down-Wall-Street-by-Burton-G-Malkiel.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090093096093099099/Sampson-Rock-of-Wall-Street-by-Edwin-Lef-vre.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9093091097093096/The-Trouble-Is-the-Banks-Letters-to-Wall-Street-by-Mark-Greif.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4097098091099093/FIASCO-Blood-in-the-Water-on-Wall-Street-by-Frank-Partnoy.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2097095099093093/Bartleby-the-Scrivener-A-Story-Of-Wall-Street-by-Herman-Melville.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4099091092095099/Bartleby-the-Scrivener-A-Story-of-Wall-Street-by-Herman-Melville.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7094099097098094/And-the-Money-Kept-Rolling-In-and-Out-Wall-Street-the-IMF-and-the-Bankrupting-of-Argentina-by-Paul-Blustein.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1098095098093095/13-Bankers-The-Wall-Street-Takeover-and-the-Next-Financial-Meltdown-by-Simon-Johnson.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7091098097095095/After-the-Fall-Saving-Capitalism-from-Wall-Street-and-Washington-by-Nicole-Gelinas.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4091090092093090/Where-Are-the-Customers-Yachts-Or-a-Good-Hard-Look-at-Wall-Street-by-Fred-Schwed-Jr-.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4098096096092092/Where-Are-the-Customers-Yachts-or-a-Good-Hard-Look-at-Wall-Street-by-Fred-Schwed.pdfIn PDF document text