Malicious PDF — malware analysis report

Static analysis result for SHA-256 c86a5f35b20e8152…

MALICIOUS

PDF

14.2 KB Created: 2019-05-02 00:48:00 +01:00 Authoring application: mPDF 5.7
MD5: 20972f69e2ffa878b3c3ca1e69cde5e3 SHA-1: b2819fecfb39b9e662747d12e2ca314d1a663db4 SHA-256: c86a5f35b20e815211b1be37773d7f31a9f9bdcf0b593234d05695a4ec155a19
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates that these links are likely intended to direct users to external content, potentially for SEO manipulation or to host malicious files. The ML classifier also flagged this PDF as malicious with a high probability. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5095099098091097/Uncanny-X-Force-by-Rick-Remender-Omnibus-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099098094097/Uncanny-X-Force-Volume-5-Otherworld-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/3090094098095090/Uncanny-X-Force-Volume-3-The-Dark-Angel-Saga-Book-1-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099098091095/Punisher-by-Rick-Remender-Omnibus-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099099094/Uncanny-Avengers-Counter-Evolutionary-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099098093096/Venom-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099092093/Tokyo-Ghost-1-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5096090090090098/Hail-Hydra-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/6096092090092099/Deadly-Class---Tome-1-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099099093/Punisher-Franken-Castle-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099090095/Deadly-Class-Vol-5-Carousel-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099092091/Fear-Agent-Volume-5-I-Against-I-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099091093/All-New-Captain-America-Hydra-Ascendant-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/3090096096093098/Black-Science-Vol-3-Vanishing-Point-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099090096/Black-Science-Vol-5-True-Atonement-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099099097/Fear-Agent-Volume-Two-Hatchet-Job-I-Against-I-Out-of-Step-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099092092/Captain-America-Volume-5-The-Tomorrow-Soldier-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/6094093096095095/Captain-America-Marvel-Now-Tome-4-Clou-de-Fer-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099098093099/Captain-America-Volume-2-Castaway-In-Dimension-Z-Book-Two-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099098094094/Black-Science-1-Black-Science-1-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/5095099099091093/All-New-Capt