Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0fd9b3db40a2445…

MALICIOUS

PDF

22.6 KB Created: 2019-04-30 05:47:13 +01:00 Authoring application: mPDF 5.7
MD5: b3b066ae90aeaf8fbb4389752c581b4c SHA-1: 717b0c1280a521679960d60fe6ebe2f73d7abfc6 SHA-256: d0fd9b3db40a24455e09892d546287cf8c37c30b1d893c6a76d112eaff9d761f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a link-farming or redirection scheme. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9092096092099092/Mosaic-Evolution-of-Subterranean-Mammals-Regression-Progression-and-Global-Convergence-by-Eviatar-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096092098092/Evolutionary-Theory-and-Processes-Modern-Perspectives-Papers-in-Honour-of-Eviatar-Nevo-by-Eviatar-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096093099091/Population-Genetics-and-Ecology-by-Nevo-Eviatar-Karlin-Samuel.pdf
    • http://loaminoo.linkpc.net/9092096092093091/Evolutionary-Theory-and-Processes-Modern-Perspectives-Papers-in-Honour-of-Eviatar-Nevo-by-Solomon-P-Wasser.pdf
    • http://loaminoo.linkpc.net/6099095097090096/The-Behavior-Guide-to-African-Mammals-Including-Hoofed-Mammals-Carnivores-Primates-by-Richard-D-Estes.pdf
    • http://loaminoo.linkpc.net/9092096092099094/Evolution-of-Wild-Emmer-and-Wheat-Improvement-Population-Genetics-Genetic-Resources-and-Genome-Organization-of-Wheat-S-Progenitor-Triticum-Dicoccoides-by-E-Nevo.pdf
    • http://loaminoo.linkpc.net/4096091093096096/The-Aquitaine-Progression-by-Robert-Ludlum.pdf
    • http://loaminoo.linkpc.net/1092098090094098/Progression-A-Sara-Grey-Tale-by-Aaron-T-Brownell.pdf
    • http://loaminoo.linkpc.net/9094093096095/Icons-of-Evolution-Science-or-Myth-Why-Much-of-What-We-Teach-About-Evolution-Is-Wrong-by-Jonathan-Wells.pdf
    • http://loaminoo.linkpc.net/4090097095099093/Evolution-Z-Stufe-Zwei-Evolution-Z---Zombie-Apokalypse-2-by-David-Bourne.pdf
    • http://loaminoo.linkpc.net/2095099096099/The-Best-of-Subterranean-by-William-Schafer.pdf
    • http://loaminoo.linkpc.net/4094098093093097/Refuting-Evolution-A-Handbook-for-Students-Parents-and-Teachers-Countering-the-Latest-Arguments-for-Evolution-by-Jonathan-Sarfati.pdf
    • http://loaminoo.linkpc.net/2098091094096092/Archangel-Evolution-The-Evolution-Trilogy-3-by-David-Estes.pdf
    • http://loaminoo.linkpc.net/3091095091096094/Demon-Evolution-The-Evolution-Trilogy-2-by-David-Estes.pdf
    • http://loaminoo.linkpc.net/6091093098093095/Multiple-Regression-A-Primer-by-Paul-D-Allison.pdf
    • http://loaminoo.linkpc.net/1090093098092095097/Alternative-Methods-Of-Regression-by-David-Birkes.pdf
    • http://loaminoo.linkpc.net/5091093098090091/Subterranean-Radio-Songs-by-Joel-Deane.pdf
    • http://loaminoo.linkpc.net/1094093093094092/Power-in-the-Global-Age-A-New-Global-Political-Economy-by-Ulrich-Beck.pdf
    • http://loaminoo.linkpc.net/1091097090092091090/Logical-Progression-Using-Nonlinear-Periodization-for-Year-Round-Climbing-Performance-by-Steve-Bechtel.pdf
    • http://loaminoo.linkpc.net/6091093098094096/Multiple-Regression-in-Behavioral-Research-by-Elazar-J-Pedhazur.pdf