Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d0efc75ef19a177…

MALICIOUS

PDF

18.2 KB Created: 2019-05-02 17:06:13 +01:00 Authoring application: mPDF 5.7
MD5: de50eb38540bddaa9e252df268f45452 SHA-1: 9ada8b26549326806c5f8160a683e2b404e46b2b SHA-256: 9d0efc75ef19a1774061e33ef039e8d816e5655ee2211aa2d87e62c6790c3a9f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While the specific URLs extracted were classified as benign, the sheer volume and structure of the link farm suggest a malicious intent to drive traffic or potentially host malicious content on a large scale. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7098094097094093/John-Bley-of-East-Leake-amp-London-1674-1731-Distiller-amp-Benefactor-by-Keith-Hodgkinson.pdf
    • http://loaminoo.linkpc.net/3092093097094096/Beyond-the-Tower-A-History-of-East-London-by-John-Marriott.pdf
    • http://loaminoo.linkpc.net/4093098098098095/Far-Flung-Floyd-Keith-Floyd-s-Guide-To-South-East-Asian-Food-by-Keith-Floyd.pdf
    • http://loaminoo.linkpc.net/5095095091099096/Family-and-Kinship-in-East-London-by-Michael-Young.pdf
    • http://loaminoo.linkpc.net/5090099095098095/A-History-of-French-Louisiana-The-Company-of-the-Indies-1723-1731-by-Marcel-Giraud.pdf
    • http://loaminoo.linkpc.net/3099099094092/East-of-Eden-by-John-Steinbeck.pdf
    • http://loaminoo.linkpc.net/6095097099092091/East-Of-Eden-by-John-Steinbeck.pdf
    • http://loaminoo.linkpc.net/2095090099095099/East-of-Eden-by-John-Steinbeck.pdf
    • http://loaminoo.linkpc.net/4093095096099098/East-of-Los-Angeles-by-John-Brantingham.pdf
    • http://loaminoo.linkpc.net/4091090090092090/East-of-Eden-by-John-Steinbeck.pdf
    • http://loaminoo.linkpc.net/1096095091092/The-Rain-John-Wells-3-by-Keith-Peterson.pdf
    • http://loaminoo.linkpc.net/4098097096093095/Keith-County-Journal-by-John-Janovy.pdf
    • http://loaminoo.linkpc.net/7095090093093090/East-of-Eden-The-Wayward-Bus-by-John-Steinbeck.pdf
    • http://loaminoo.linkpc.net/1094092095094095/How-to-Be-Idle-by-Tom-Hodgkinson.pdf
    • http://loaminoo.linkpc.net/3091099099098091/How-To-Be-Free-by-Tom-Hodgkinson.pdf
    • http://loaminoo.linkpc.net/9095096098096099/The-East-Lancashire-Regiment-1855-1958-by-John-Downham.pdf
    • http://loaminoo.linkpc.net/2091090097099091/Oregon-s-Dry-Side-Exploring-East-of-the-Cascade-Crest-by-Alan-D-St-John.pdf
    • http://loaminoo.linkpc.net/3099092090093091/The-Buddha-in-the-Machine-Art-Technology-and-the-Meeting-of-East-and-West-by-R-John-Williams.pdf
    • http://loaminoo.linkpc.net/7094097097095096/Articles-on-Anarcho-Primitivists-Including-John-Zerzan-John-Moore-Anarchist-Derrick-Jensen-Fredy-Perlman-Andy-Hurley-David-Watson-Anarchist-Thomas-Toivonen-Ted-Kaczynski-Kevin-Tucker-Lierre-Keith-Istva-N-CS-Bartos-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/4095094093099093/Spilt-Milk-by-Amanda-Hodgkinson.pdf
    • http://loaminoo.linkpc.net/1096095091092/The-Rain-John-Wells-3-by