Malicious PDF — malware analysis report

Static analysis result for SHA-256 c35d78da6b351b58…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 09:03:30 +01:00 Authoring application: mPDF 5.7
MD5: 98b563f82e00f161a272655355a91c8b SHA-1: accd123de6916bd93eb0198725bd5f9c229cb6d6 SHA-256: c35d78da6b351b58b4c3aa62cc03ede62204d6ebad7ada2ea853466b20e96fbd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, forming a link farm. These links likely serve as a lure to direct users to potentially malicious content or phishing pages. The ML classifier's high confidence score supports this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090094090097097095/Jerry-Cotton---Folge-3005-Der-Tod-stellt-viele-Fragen-by-Jerry-Cotton.pdf
    • http://loaminoo.linkpc.net/1091094095099091092/Jerry-Cotton---Folge-2850-Liebe-ist-ein-hartes-Gesch-ft-by-Jerry-Cotton.pdf
    • http://loaminoo.linkpc.net/1090098097098092098/Jerry-Cotton-Sonder-Edition---Folge-001-Ein-teuflischer-Plan-by-Jerry-Cotton.pdf
    • http://loaminoo.linkpc.net/1090092090091095092/Jerry-Cotton---Folge-2908-Die-Fackel-der-Vergeltung-by-Jerry-Cotton.pdf
    • http://loaminoo.linkpc.net/1091091090096096098/Jerry-Cotton---Folge-2826-Bomben-in-Manhattan-by-Jerry-Cotton.pdf
    • http://loaminoo.linkpc.net/8099093097093091/Jerry-Cotton---Folge-2884-Im-Netz-der-Spinne-by-Jerry-Cotton.pdf
    • http://loaminoo.linkpc.net/9092098091094091/Jerry-Cotton---Folge-2171-Das-L-cheln-der-Tigerin-by-Jerry-Cotton.pdf
    • http://loaminoo.linkpc.net/1090097091094094097/Jerry-Cotton---Folge-2958-Am-Ziel-wartet-der-Tod-by-Jerry-Cotton.pdf
    • http://loaminoo.linkpc.net/3091090094098099/Gone-on-Sunday-A-Cotton-Lee-Penn-Historical-Mystery-Cotton-Lee-Penn-Historical-Mysteries-Book-1-by-Tower-Lowe.pdf
    • http://loaminoo.linkpc.net/5098092097094097/The-Reprobate-How-Reprobates-Destroy-our-Future-Also-includes-The-Walking-Dead-a-novel-by-Jerry-Henrie-by-Jerry-Henrie.pdf
    • http://loaminoo.linkpc.net/1095095094090091/Jerry-D-Young-s-Survival-Fiction-Library-Book-One-The-Hermit-by-Jerry-D-Young.pdf
    • http://loaminoo.linkpc.net/3097095093096090/The-Cotton-Pickers-by-B-Traven.pdf
    • http://loaminoo.linkpc.net/3095094096097092/Boundless-by-Brad-Cotton.pdf
    • http://loaminoo.linkpc.net/8093091093099096/Guy-Bourdin-by-Charlotte-Cotton.pdf
    • http://loaminoo.linkpc.net/2099092093095096/Cotton-Comes-To-Harlem-by-Chester-Himes.pdf
    • http://loaminoo.linkpc.net/1092094094094090/High-Cotton-Maafa-by-P-J-Dunn.pdf
    • http://loaminoo.linkpc.net/1095099093091091/Cotton-Patch-Gospel-Musical-by-Tom-Key.pdf
    • http://loaminoo.linkpc.net/1090096090094098097/Webb-s-Posse-by-Ralph-Cotton.pdf
    • http://loaminoo.linkpc.net/9099093094093094/The-Birthmark-by-Mary-Wiggins-Cotton.pdf
    • http://loaminoo.linkpc.net/1094098095095092/Cotton-Satan-s-Fury-MC-3-by-L-Wilder.pdf
    • http://loaminoo.linkpc.net/3091090094098099/Gone-on-Sunday-A-Cotton-Lee-Penn-Historical-Mystery-Cotton-Lee-Penn-Historical-Mysteries-Book-1-by-Tower-L