Malicious PDF — malware analysis report

Static analysis result for SHA-256 94e04b61f0b174a9…

MALICIOUS

PDF

20.1 KB Created: 2019-05-02 02:25:14 +01:00 Authoring application: mPDF 5.7
MD5: 98909482e6223f2f2e7f04770ba407d3 SHA-1: d6f29b6c8f74be59830c40d38ee1d0ebb8466148 SHA-256: 94e04b61f0b174a98f15de58667582270feecdc03abb29ea4998e0e0178dfc2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be SEO poisoning or directing users to potentially malicious content through a large number of links. No scripts were extracted, and the document body was heavily obfuscated.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6091099099090096/Uncle-Tom-s-Cabin-Or-Life-Among-the-Lowly-1852-by-Harriet-Beecher-Stowe-The-REV-James-Sherman-21-February-1796---15-February-1862-Was-an-English-Congregationalist-Minister-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5097090093098095/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091093098093099098/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/7090094098091099/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091097093091098096/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/3095093095098097/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5092097099099095/Uncle-Tom-s-Cabin-or-Life-among-the-Lowly-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5098098091090093/Uncle-Tom-s-Cabin-The-Original-Classics---Illustrated-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1090098092090093095/Onkel-Toms-H-tte-Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1090095096092093098/Harriet-Beecher-Stowe---Uncle-Tom-s-Cabin-quot-We-First-Make-Our-Habits-Then-Our-Habits-Make-Us-quot-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/2095091092097095/12-Years-A-Slave-True-story-of-an-African-American-who-was-kidnapped-in-New-York-and-sold-into-slavery---with-bonus-material-Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe-by-Solomon-Northup.pdf
    • http://loaminoo.linkpc.net/1091092090097098096/Life-Of-Harriet-Beecher-Stowe-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1090093090095093096/Agnes-of-Sorrento-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5098099096090099/A-Cabana-do-Pai-Tom-s-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/2097093097098099/Pink-and-White-Tyranny-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/8095097092098099/Pink-and-White-Tyranny-a-Society-Novel-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091091090092095095/De-hut-van-oom-Tom-Een-verhaal-uit-het-slavenleven-in-Noord-Amerika-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091092090098094096/A-Picture-Book-of-Harriet-Beecher-Stowe-by-David-A-Adler.pdf
    • http://loaminoo.linkpc.net/4095090094090/Harriet-Beecher-Stowe-A-Spiritual-Life-by-Nancy-Koester.pdf
    • http://loaminoo.linkpc.net/1091092090099091096/Harriet-Beecher-Stowe-Connecticut-Girl-by-Mabel-Cleland-Widdemer.pdf