Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d36f09ade40c3f4…

MALICIOUS

PDF

20.0 KB Created: 2019-05-02 02:38:46 +01:00 Authoring application: mPDF 5.7
MD5: f1fe8c4c549f208da69b60be50f8fbd6 SHA-1: d2707b756a14ecdf334a1fff48c0f739643fc589 SHA-256: 9d36f09ade40c3f41d5c2fc2c1f8060aea8c89a501eb8002f74421bd692ffaac
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier with high confidence and contains a large number of external links, many of which point to PDF files with numeric slugs. The primary heuristic indicates a 'PDF_SEO_LINK_FARM', suggesting the document's purpose is to manipulate search engine results or distribute content via a link farm. While no scripts were extracted, the embedded URLs and the nature of the link farm suggest a malicious intent to redirect users to potentially harmful content or exploit SEO tactics for malicious purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092096099090090/That-Oxford-Girl-A-Real-Student-s-Guide-to-Oxford-University-by-Tilly-Rose.pdf
    • http://loaminoo.linkpc.net/4092095096094098/Oxford-Whispers-The-Oxford-Saga-1-by-Marion-Croslydon.pdf
    • http://loaminoo.linkpc.net/2094092093090097/My-Oxford-My-Cambridge-Memories-of-University-Life-by-Twenty-Four-Distinguished-Graduates-by-Ann-Thwaite.pdf
    • http://loaminoo.linkpc.net/5092098093094093/Oxford-University-Papers-on-India-Volume-2-Part-1-Indian-Ritual-and-Its-Exegesis-by-Richard-F-Gombrich.pdf
    • http://loaminoo.linkpc.net/1091099094095096092/Ludvig-Holberg-The-Founder-of-Norwegian-Literature-and-an-Oxford-Student-by-Simon-Christian-Hammer.pdf
    • http://loaminoo.linkpc.net/2098099097095092/The-New-Oxford-Book-of-American-Verse-Oxford-Books-of-Verse-by-Richard-Ellmann.pdf
    • http://loaminoo.linkpc.net/7093090090090096/Dictionary-of-Physics-Derived-from-the-Concise-Science-Dictionary-by-Oxford-University-Press.pdf
    • http://loaminoo.linkpc.net/1094090097096094/Shakespeare-An-Oxford-Guide-by-Stanley-Wells.pdf
    • http://loaminoo.linkpc.net/6096092095090094/The-Dodo-Guide-To-Oxford-by-Philip-Atkins.pdf
    • http://loaminoo.linkpc.net/4099090094099094/Oxford-Outside-The-Guide-Books-by-Falconer-Madan.pdf
    • http://loaminoo.linkpc.net/1091091098093093090/Real-Food-University-Cookbook-Volume-2---Sides-amp-Salads-Real-Food-University-Cookbooks-by-Scott-Kustes.pdf
    • http://loaminoo.linkpc.net/1091091098091095093/Real-Food-University-Cookbook-Volume-4---Poultry-Real-Food-University-Cookbooks-by-Scott-Kustes.pdf
    • http://loaminoo.linkpc.net/1091091098091095097/Real-Food-University-Cookbook-Volume-5---Seafood-Real-Food-University-Cookbooks-by-Scott-Kustes.pdf
    • http://loaminoo.linkpc.net/3094091094090095/Someone-Like-You-Oxford-3-by-Lauren-Layne.pdf
    • http://loaminoo.linkpc.net/4093091092093094/The-Oxford-Deception-by-Craig-Janacek.pdf
    • http://loaminoo.linkpc.net/2097092093097094/Everything-is-Perfect-When-You-re-a-Liar-by-Kelly-Oxford.pdf
    • http://loaminoo.linkpc.net/3090091095099097/Surprised-by-Oxford-by-Carolyn-Weber.pdf
    • http://loaminoo.linkpc.net/2096097092093090/My-Oxford-Year-by-Julia-Whelan.pdf
    • http://loaminoo.linkpc.net/4096098097095095/The-Contract-The-Masters-of-Oxford-1-by-Natalie-Dae.pdf
    • http://loaminoo.linkpc.net/9091098095098091/The-Oxford-Book-of-the-Supernatural-by-D-J-Enright.pdf
    • http://loaminoo.linkpc.net/1091