Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf092b7c887a8407…

MALICIOUS

PDF

20.6 KB Created: 2019-04-30 04:32:12 +01:00 Authoring application: mPDF 5.7
MD5: c07612dacdd7981fdec8860b929fdb11 SHA-1: f4650a24af55382b379c8225144dfee5dbd39a6e SHA-256: bf092b7c887a8407a0f2e90d26693e1a925a0667ecaf694a6257d4beb703d04e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a machine learning classifier and contains a large number of embedded URLs, indicating a link farm. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent, likely for SEO manipulation or to distribute further payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090096096092095091/Integrated-Pharmacology-Combining-Modern-Pharmacology-with-Chinese-Medicine-by-Greg-Sperber.pdf
    • http://loaminoo.linkpc.net/8099099095091091/Pharmacology-by-Christopher-Herz.pdf
    • http://loaminoo.linkpc.net/5094099095096098/Principles-of-Pharmacology-by-H-L-Sharma.pdf
    • http://loaminoo.linkpc.net/6093091094094094/AIDS-to-Clin-Pharmacology-Therapeutcs-3e-by-Jonathan-Reese.pdf
    • http://loaminoo.linkpc.net/5098094090099092/Chemistry-and-Pharmacology-of-Anticancer-Drugs-by-David-Thurston.pdf
    • http://loaminoo.linkpc.net/8092095092094092/Pharmacology-And-Therapeutics-In-Respiratory-Care-by-Theodore-J-Witek.pdf
    • http://loaminoo.linkpc.net/9097090092091093/Essay-approach-to-addiction-pharmacology-Chemical-Treatment-for-Behaviors-by-Fredy-Martinez.pdf
    • http://loaminoo.linkpc.net/5092093098096099/Molecular-Biology-and-Pharmacology-of-Cyclic-Nucleotides-Proceedings-of-the-NATO-Advanced-Study-Institute-on-Cyclic-Nucleotides-Held-in-Tremezzo-Com-by-Giancarlo-Folco.pdf
    • http://loaminoo.linkpc.net/9093097091090097/Mavericks-Miracles-and-Medicine-The-Pioneers-Who-Risked-Their-Lives-to-Bring-Medicine-into-the-Modern-Age-by-Julie-M-Fenster.pdf
    • http://loaminoo.linkpc.net/7091093095091095/Integrated-Aromatic-Medicine-Proceedings-from-the-First-International-Symposium-Held-in-Grasse-France-March-21-22-1998-by-Essential-Science-Publishing.pdf
    • http://loaminoo.linkpc.net/1099096096093092/Other-Worldly-Making-Chinese-Medicine-through-Transnational-Frames-by-Mei-Zhan.pdf
    • http://loaminoo.linkpc.net/4092099090093091/The-Heart-of-Chinese-Poetry-by-Greg-Whincup.pdf
    • http://loaminoo.linkpc.net/7091095095090098/Sun-Tzu-s-Art-of-War-The-Modern-Chinese-Interpretation-by-Sun-Tzu.pdf
    • http://loaminoo.linkpc.net/1090096096091099090/Der-Sperber-in-Deutschland-by-Sp-Interessengemeinschaft-Sperber-Igs-.pdf
    • http://loaminoo.linkpc.net/2095094091099094/The-History-of-New-Innovations-in-Modern-Medicine-by-James-D-Okun.pdf
    • http://loaminoo.linkpc.net/5095099097094095/The-Columbia-Anthology-of-Modern-Chinese-Literature-by-Joseph-S-M-Lau.pdf
    • http://loaminoo.linkpc.net/1090097098099094095/Modern-Chinese-Warfare-1795-1989-by-Bruce-A-Elleman.pdf
    • http://loaminoo.linkpc.net/9095093099091096/Chinese-Astrology-Ancient-Secrets-for-Modern-Life-by-Sabrina-Liao.pdf
    • http://loaminoo.linkpc.net/1091094099090097096/Pien-Chih-Lin-A-Study-in-Modern-Chinese-Poetry-by-Lloyd-Haft.pdf
    • http://loaminoo.linkpc.net/4094093093091095/Tiger-s-Heart-The-Story-of-a-Modern-Chinese-Woman-by-Aisling-Juanjuan-Shen.pdf
    • http://loaminoo.linkpc.net/5092093