Malicious PDF — malware analysis report

Static analysis result for SHA-256 a94eb6fa4d1b84ba…

MALICIOUS

PDF

15.5 KB Created: 2019-05-02 01:42:44 +01:00 Authoring application: mPDF 5.7
MD5: e2f50cb26a7752a7234285f7e0370dbf SHA-1: fcdd3659bfcbd68c2d9aada4c842cc38f8cc0c93 SHA-256: a94eb6fa4d1b84ba928da1b83fba394b6b5d26047cd2f4c6ef30e333ad6994a4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4098099092092096/Death-in-a-Difficult-Position-Mantra-for-Murder-4-by-Diana-Killian.pdf
    • http://loaminoo.linkpc.net/6094093093096/Full-Circle-A-True-Story-of-Murder-Lies-and-Vindication-by-Gloria-Killian.pdf
    • http://loaminoo.linkpc.net/1090095095098093098/The-Warrior-s-Mantra-by-Rodger-Ruge.pdf
    • http://loaminoo.linkpc.net/8094096093096094/Septi-me-Mantra-Feeling-Good-7-by-Fleur-Hana.pdf
    • http://loaminoo.linkpc.net/2096099091090/Honeymoon-With-Murder-Death-on-Demand-4-by-Carolyn-G-Hart.pdf
    • http://loaminoo.linkpc.net/3091094091096099/The-Death-Panel-Murder-Mayhem-and-Madness-by-Tom-Piccirilli.pdf
    • http://loaminoo.linkpc.net/2097092094092/A-Little-Class-on-Murder-Death-on-Demand-5-by-Carolyn-G-Hart.pdf
    • http://loaminoo.linkpc.net/9097090094091096/Neptolon-11011-Gl-cklich-g-ttlich-und-dadurch-unsterblich-by-Mantra-Galactika.pdf
    • http://loaminoo.linkpc.net/2091095097090099/Death-by-Government-Genocide-and-Mass-Murder-Since-1900-by-R-J-Rummel.pdf
    • http://loaminoo.linkpc.net/1090094099095097094/Death-in-an-English-Cottage-Murder-on-Location-2-by-Sara-Rosett.pdf
    • http://loaminoo.linkpc.net/3094093096099094/Hasty-Death-Edwardian-Murder-Mysteries-2-by-Marion-Chesney.pdf
    • http://loaminoo.linkpc.net/3095098090096097/Murder-Bayou-Style-Death-in-the-Swamps-by-Gary-Graybill.pdf
    • http://loaminoo.linkpc.net/2091095096092099/Death-by-Cannibal-Minds-with-an-Appetite-for-Murder-by-Peter-Davidson.pdf
    • http://loaminoo.linkpc.net/1090096099097099093/Sacred-Sound-Discovering-the-Myth-and-Meaning-of-Mantra-and-Kirtan-by-Alanna-Kaivalya.pdf
    • http://loaminoo.linkpc.net/1091095093091099/12-21-12-by-Killian-McRae.pdf
    • http://loaminoo.linkpc.net/4093098097092/Murder-in-Amsterdam-The-Death-of-Theo-van-Gogh-and-the-Limits-of-Tolerance-by-Ian-Buruma.pdf
    • http://loaminoo.linkpc.net/1096095097097/Till-Death-Us-Do-Part-A-True-Murder-Mystery-by-Vincent-Bugliosi.pdf
    • http://loaminoo.linkpc.net/1097092093092/Talked-to-Death-The-Life-and-Murder-of-Alan-Berg-by-Stephen-Singular.pdf
    • http://loaminoo.linkpc.net/1091090093092096094/Murder-in-Benin-Kate-Puzey-s-Death-in-the-Peace-Corps-by-Aaron-Kase.pdf
    • http://loaminoo.linkpc.net/3099090090097095/The-Mysterious-Death-of-Mr-Darcy-Pride-and-Prejudice-Murder-Mystery-3-by-Regina-Jeffers.pdf