Malicious PDF — malware analysis report

Static analysis result for SHA-256 b106a11ea3c18584…

MALICIOUS

PDF

23.6 KB Created: 2019-05-02 17:48:51 +01:00 Authoring application: mPDF 5.7
MD5: e65e1ba10cc68774d72968db620be69a SHA-1: 6f006b292538e4b4b2422befe6e974f5b635a200 SHA-256: b106a11ea3c18584b04b42733f6aea116fed2ef746603ef1e866e8b2fddb6f79
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this file as malicious with high confidence. The embedded URLs appear to be part of a link farm designed to direct users to various book-related PDFs, likely as a lure for further malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097093092095091/English-Short-Stories-with-Audio-Files-Intermediate-Level-English-Fluency-Practice-Intermediate-Level-Book-4-by-Alexander-Pavlenko.pdf
    • http://loaminoo.linkpc.net/7097093091091098/English-Short-Stories-Intermediate-Level-English-Fluency-Practice-Intermediate-Level-Book-4-by-Alexander-Pavlenko.pdf
    • http://loaminoo.linkpc.net/8096090095092096/Modern-British-And-American-English-Pronunciation-A-Basic-Textbook-by-Burkhard-Dretzke.pdf
    • http://loaminoo.linkpc.net/5096098095090092/Intermediate-English-Grammar-A-Guide-for-New-and-Prospective-ESL-Teachers-by-Miles-Jaworski.pdf
    • http://loaminoo.linkpc.net/4096097099095099/English-Grammar-in-Use-with-Answers-Reference-and-Practice-for-Intermediate-Students-by-Raymond-Murphy.pdf
    • http://loaminoo.linkpc.net/7097093091098094/Accents-Personal-Stories-English-Fluency-Practice-Intermediate-Level-Book-6-by-Alexander-Pavlenko.pdf
    • http://loaminoo.linkpc.net/1090095091097097093/Taking-Off-Beginning-English-Te-With-Tests-by-Susan-Hancock-Fesler.pdf
    • http://loaminoo.linkpc.net/1090095091097097098/Taking-Off-English-Literacy-Workbook-on-CD-by-Susan-Hancock-Fesler.pdf
    • http://loaminoo.linkpc.net/1090095091096094097/Taking-Off-Beginning-English-Workbook-2nd-Edition-by-Fesler-Susan-Hancock.pdf
    • http://loaminoo.linkpc.net/1090095091097097094/Taking-Off-Beginning-English-Literacy-Workbook-by-Susan-Hancock-Fesler.pdf
    • http://loaminoo.linkpc.net/1090095091096093092/Taking-Off-Beginning-English-Student-Book-2nd-Edition-by-Fesler-Susan-Hancock.pdf
    • http://loaminoo.linkpc.net/9091092099090093/English-German-Bible---The-Gospels-XX---Matthew-Mark-Luke-amp-John-Basic-English-1949---Elberfelder-1905---Lutherbibel-1545-Parallel-Bible-Halseth-English-Book-935-by-Truthbetold-Ministry.pdf
    • http://loaminoo.linkpc.net/1090095091096093091/Taking-Off-Beginning-English-2nd-Edition---USA-Post-Test-Study-Guide-by-Fesler-Susan-Hancock.pdf
    • http://loaminoo.linkpc.net/1090098095095092090/Jen-Hancock-s-Handy-Humanism-Handbook-by-Jennifer-Hancock.pdf
    • http://loaminoo.linkpc.net/1090095091097093092/Taking-Off-Student-Book-with-Audio-Highlights-Literacy-Workbook-Workbook-Package-Beginning-English-by-Fesler-Susan-Hancock.pdf
    • http://loaminoo.linkpc.net/6099095099092098/Reminiscences-of-Winfield-Scott-Hancock-by-A-R-Hancock.pdf
    • http://loaminoo.linkpc.net/1090098095095097091/Hancock-On-Hancock-by-Michael-Doyle.pdf
    • http://loaminoo.linkpc.net/1090098095092096092/The-Divine-Spark-A-Graham-Hancock-Reader-by-Graham-Hancock.pdf
    • http://loaminoo.linkpc.net/1090098095093091095/Hancock-by-Freddie-Hancock.pdf
    • http://loaminoo.linkpc.net/1091093090094090090/Elementary-Modern-Standard-Arabic-Volume-1-Pronunciation-and-Writing-Lessons-1-30-by-Peter-F-Abboud.pdf
    • http://loaminoo.linkpc.net/4096097099095099/English-Grammar-in-Use-with-Answers-Reference-an