Malicious PDF — malware analysis report

Static analysis result for SHA-256 983bc7e769d88b92…

MALICIOUS

PDF

13.2 KB Created: 2019-05-02 19:08:56 +01:00 Authoring application: mPDF 5.7
MD5: 30edacd87182a0ccd2d17f06c36df819 SHA-1: 143819db725c96a664f9ef62c691144bf9fe0ebd SHA-256: 983bc7e769d88b926b7faf2d67f4bab25cfd55dd186cde058e6611b80fc300fe
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates this is a technique to artificially inflate search engine rankings or distribute malicious content. While the specific intent beyond linking is unclear due to the lack of executable scripts, the sheer volume of links suggests a malicious distribution or SEO poisoning campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9006

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9093090090091091/A-Deeper-Blue-by-Regina-Hanel.pdf
    • http://loaminoo.linkpc.net/1092094093093/Out-Of-The-Blue-by-Jill-Shalvis.pdf
    • http://loaminoo.linkpc.net/2091097093091096/Blue-Flame-Firefighter-2-by-Jill-Shalvis.pdf
    • http://loaminoo.linkpc.net/3096092098095095/Summers-at-Blue-Lake-by-Jill-Althouse-Wood.pdf
    • http://loaminoo.linkpc.net/3096095099096094/Blue-Moon-The-Runaways-3-by-Jill-Marie-Landis.pdf
    • http://loaminoo.linkpc.net/2094094091097092/Jill-s-Riding-Club-Jill-s-Ponies-5-by-Ruby-Ferguson.pdf
    • http://loaminoo.linkpc.net/2094094091097099/Jill-s-Pony-Trek-Jill-s-Ponies-9-by-Ruby-Ferguson.pdf
    • http://loaminoo.linkpc.net/1096099099093093/Deeper-by-Megan-Hart.pdf
    • http://loaminoo.linkpc.net/3097097097095094/Deeper-by-Ronica-Black.pdf
    • http://loaminoo.linkpc.net/5091093095090/A-Deeper-Cut-by-Sheri-Wren-Haymore.pdf
    • http://loaminoo.linkpc.net/9097096097099094/Dominante-Kerle-6-in-1-by-Alice-Deeper.pdf
    • http://loaminoo.linkpc.net/1096091094093094/Deeper-into-the-Void-by-Mitchell-A-Duncan.pdf
    • http://loaminoo.linkpc.net/4090092099099090/Deeper-Hammer-21-by-Sean-Michael.pdf
    • http://loaminoo.linkpc.net/8093092090095099/Jill-Prescott-s-Ecole-De-Cuisine-Professional-Cooking-for-the-Home-Chef-by-Jill-Prescott.pdf
    • http://loaminoo.linkpc.net/2098090094099093/Samurai-Deeper-Kyo-Volume-01-by-Akimine-Kamijyo.pdf
    • http://loaminoo.linkpc.net/3090092094094090/The-Deeper-We-Get-The-Harder-I-Fall-2-by-Jessica-Gibson.pdf
    • http://loaminoo.linkpc.net/7092099095097095/The-Deeper-the-Water-the-Uglier-the-Fish-by-Katya-Apekina.pdf
    • http://loaminoo.linkpc.net/3094092091099097/Drawn-Deeper-Lockhart-Brothers-3-by-Brenda-Rothert.pdf
    • http://loaminoo.linkpc.net/6094092099094098/Five-Points-Towards-a-Deeper-Experience-of-God-s-Grace-by-John-Piper.pdf
    • http://loaminoo.linkpc.net/2098096091096095/A-Deeper-Sleep-Kate-Shugak-15-by-Dana-Stabenow.pdf
    • http://loaminoo.linkpc.net/8093092090095099/Jill-Prescott-s-Ecole-De-