Malicious PDF — malware analysis report

Static analysis result for SHA-256 b69f49e2d36eaa4b…

MALICIOUS

PDF

16.7 KB Created: 2019-05-05 16:54:42 +01:00 Authoring application: mPDF 5.7
MD5: df2f58ef4351f6553cea79643ea79b11 SHA-1: 9e4ac4b5989206b9218cca1ebdb732d4a9e4ba31 SHA-256: b69f49e2d36eaa4bfdd4f527397bfedff6297222c829bab3e071c2370b81af7d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by an ML classifier as malicious and contains a large number of embedded links, indicating a potential link farm or distribution point for further malicious content. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this is the primary malicious function. While no scripts were extracted, the sheer volume of links and the ML classification point to a malicious intent, likely related to SEO abuse or hosting malware. The URLs themselves appear to be benign, but their quantity and context are suspicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5099097098094096/The-Book-Thief-by-Markus-Zusak----Review-by-Expert-Book-Reviews.pdf
    • http://loaminoo.linkpc.net/7090097098094091/The-Book-Thief-by-Markus-Zusak---REVIEW-and-SUMMARY-guide-by-Easy2Digest-Summaries.pdf
    • http://loaminoo.linkpc.net/6093095098093/The-Book-Thief-by-Markus-Zusak.pdf
    • http://loaminoo.linkpc.net/4093090092097/The-Book-Thief-by-Markus-Zusak.pdf
    • http://loaminoo.linkpc.net/3098098098099/The-Book-Thief-by-Markus-Zusak.pdf
    • http://loaminoo.linkpc.net/2095095093097091/The-Book-Thief-by-Markus-Zusak.pdf
    • http://loaminoo.linkpc.net/3097095099094092/The-Book-Thief-by-Markus-Zusak.pdf
    • http://loaminoo.linkpc.net/5092099094092/The-Book-Thief-by-Markus-Zusak.pdf
    • http://loaminoo.linkpc.net/4090098092096/The-Book-Thief-by-Markus-Zusak.pdf
    • http://loaminoo.linkpc.net/9098099090097096/Missing-You-by-Harlan-Coben----Review-by-Expert-Book-Reviews.pdf
    • http://loaminoo.linkpc.net/8097091098096097/The-Goldfinch-by-Donna-Tartt----Review-by-Expert-Book-Reviews.pdf
    • http://loaminoo.linkpc.net/6096094096091/The-Invention-of-Wings-by-Sue-Monk-Kidd----Review-by-Expert-Book-Reviews.pdf
    • http://loaminoo.linkpc.net/7090097097099093/The-Book-Thief-by-Markus-Zusak----Analysis-by-BookBuddy.pdf
    • http://loaminoo.linkpc.net/7090097098093098/The-Book-Thief-Markus-Zusak-by-Editorial-Europa.pdf
    • http://loaminoo.linkpc.net/7090097098094090/The-Unauthorized-Guide-to-the-History-Behind-Markus-Zusak-s-the-Book-Thief-by-Skyler-Collins.pdf
    • http://loaminoo.linkpc.net/7090097098095099/Summary-of-The-Book-Thief-by-Markus-Zusak-Trivia-Quiz-for-Fans-by-Whiz-Books.pdf
    • http://loaminoo.linkpc.net/7090097098095098/An-Unauthorized-Guide-to-Markus-Zusak-A-Short-Biography-of-the-Author-of-The-Book-Thief-Article-by-Malcolm-Stone.pdf
    • http://loaminoo.linkpc.net/7090097097099098/The-Book-Thief-A-Novel-by-Markus-Zusak-Trivia-On-Books-by-Trivion-Books.pdf
    • http://loaminoo.linkpc.net/4096098090093092/When-Dogs-Cry-by-Markus-Zusak.pdf
    • http://loaminoo.linkpc.net/3093092097090090/The-Pot-Thief-Who-Studied-Georgia-O-Keeffe-The-Pot-Thief-Mysteries-Book-7-by-J-Michael-Orenduff.pdf
    • http://loaminoo.linkpc.net/809709109809