Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf3afa110c5dacf5…

MALICIOUS

PDF

16.5 KB Created: 2019-05-01 20:07:09 +01:00 Authoring application: mPDF 5.7 First seen: 2020-12-28
MD5: c27ecf44195c8a8ea4c098f54c646404 SHA-1: 88eaab033d1751cf93cd8a2c3f889ba1df7c3509 SHA-256: bf3afa110c5dacf575270ae26d46bfa21f7d4113b8921ead2437beeb8c6158bc
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files hosted on a dynamic DNS domain. This heuristic firing, combined with the ML classifier, indicates a malicious intent to redirect users to potentially harmful content. The document body, though heavily obfuscated, contains these URLs, reinforcing the link farm attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092090091095098/Eye-Candy-Candy-3-by-Amanda-Young.pdf In PDF document text
    • http://loaminoo.linkpc.net/3090096092090096/Man-Candy-Candy-1-by-Amanda-Young.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4090090092093/L-A-Candy-L-A-Candy-1-by-Lauren-Conrad.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6099098099098091/Frederick-s-Journey-The-Life-of-Frederick-Douglass-by-Doreen-Rappaport.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5095090090096091/Narrative-of-the-Life-of-Frederick-Douglass-with-Cherokee-Removal-amp-Great-Awakening-by-Frederick-Douglass.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090094092090095099/Narrative-of-the-Life-of-Frederick-Douglass-an-American-Slave-with-eBook-by-Frederick-Douglass.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4090091092095099/Narrative-of-the-Life-of-Frederick-Douglass-An-American-Slave-and-Essays-by-Frederick-Douglass.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2098093098090091/Narrative-of-the-Life-of-Frederick-Douglass-An-American-Slave-by-Frederick-Douglass.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6090091091095096/Narrative-of-the-Life-of-Frederick-Douglass-and-American-Slave-by-Frederick-Douglass.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2097091095091095/Narrative-of-the-Life-of-Frederick-Douglass-an-American-Slave-by-Frederick-Douglass.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6099099090093092/Inzone-Books-Narrative-of-the-Life-of-Frederick-Douglass-by-Frederick-Douglass.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5099090095099097/Narrative-of-the-Life-of-Frederick-Douglass-an-American-Slave-by-Frederick-Douglass.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5096090092096097/Pampered-by-Germaine-Solomon.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2097091092095096/Devious-Minds-by-K-F-Germaine.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5096090093098099/Delphine-by-Germaine-de-Sta-l.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5094099095095096/Gide-by-Germaine-Br-e.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5096090093097099/Prayers-That-Avail-Much-by-Germaine-Copeland.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5096090092096094/Germaine-Greer-by-Frederic-P-Miller.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2094095096098098/Daddy-We-Hardly-Knew-You-by-Germaine-Greer.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1094090099090097/Shakespeare-s-Wife-by-Germaine-Greer.pdfIn PDF document text