Malicious PDF — malware analysis report

Static analysis result for SHA-256 c08e9f861a66abd5…

MALICIOUS

PDF

14.9 KB Created: 2019-04-30 06:46:18 +01:00 Authoring application: mPDF 5.7
MD5: ecb019399c90bf103b2b6e0c67ad8b7e SHA-1: 2a1c85f17ec2082dab80f09c195c60b711c6d830 SHA-256: c08e9f861a66abd5270e3f569d120d094d8212343ea7242ef03df3c8b4bc5dd1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to other PDF files hosted on the same domain, suggesting a link farm or a method to distribute malicious content. While the document body is heavily corrupted, the presence of numerous links and the ML classifier's high confidence score indicate a malicious intent, likely related to SEO manipulation or hosting further stages of an attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9094094093098099/What-Makes-You-Cough-Sneeze-Burp-Hiccup-Blink-Yawn-Sweat-and-Shiver-by-Jean-Stangl.pdf
    • http://loaminoo.linkpc.net/8093092093099094/Why-I-Sneeze-Shiver-Hiccup-Yawn-by-Melvin-A-Berger.pdf
    • http://loaminoo.linkpc.net/9094094093098096/Crystals-and-Crystal-Gardens-You-Can-Grow-Full-Color-First-Books-by-Jean-Stangl.pdf
    • http://loaminoo.linkpc.net/4099095097097099/Shiver-Quartet-Shiver-Linger-Forever-Sinner-by-Maggie-Stiefvater.pdf
    • http://loaminoo.linkpc.net/9094094093098097/Learning-Statistics-in-the-Lab-by-Stangl.pdf
    • http://loaminoo.linkpc.net/3092092099099099/The-Big-Sneeze-by-Bill-Blume.pdf
    • http://loaminoo.linkpc.net/1094095095095090/Horace-Burp-Lizard-Boy-by-Christine-Tennent.pdf
    • http://loaminoo.linkpc.net/1093097098099093/Hiccup-Champion-Of-The-World-by-Ken-Roberts.pdf
    • http://loaminoo.linkpc.net/1091094090094092/I-Dare-You-Not-to-Yawn-by-Helene-Boudreau.pdf
    • http://loaminoo.linkpc.net/6094098090094091/Shakespeare-s-Tremor-and-Orwell-s-Cough-The-Medical-Lives-of-Famous-Writers-by-John-J-Ross.pdf
    • http://loaminoo.linkpc.net/2099093094092098/How-to-Cheat-a-Dragon-s-Curse-Hiccup-Horrendous-Haddock-III-4-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/3094090093093091/Shiver-by-Ella-Frank.pdf
    • http://loaminoo.linkpc.net/2093090094098095/Shiver-by-Nikki-Gemmell.pdf
    • http://loaminoo.linkpc.net/4090092094098099/Shiver-by-Ella-Frank.pdf
    • http://loaminoo.linkpc.net/4094098097092091/Blink-Once-by-Cylin-Busby.pdf
    • http://loaminoo.linkpc.net/4096097095098091/Blink-of-an-Eye-by-Cath-Staincliffe.pdf
    • http://loaminoo.linkpc.net/6093092093096/In-the-Blink-of-an-Eye-by-Walter-Murch.pdf
    • http://loaminoo.linkpc.net/2090095090097090/In-a-Blink-by-Kiki-Thorpe.pdf
    • http://loaminoo.linkpc.net/1098098091092091/Blink-Once-by-Cylin-Busby.pdf
    • http://loaminoo.linkpc.net/1096095092096096/Shiver-New-Orleans-3-by-Lisa-Jackson.pdf
    • http://loaminoo.linkpc.net/609409