Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1e2c6ae3de4621e…

MALICIOUS

PDF

15.1 KB Created: 2019-05-01 19:26:13 +01:00 Authoring application: mPDF 5.7
MD5: d12ff76287d1bb8263c612b81479be5e SHA-1: 937f7cff02f32e611dfeabb3ba046dabd2417e49 SHA-256: d1e2c6ae3de4621e9a7a68a69a52dd87f55c339186eab1cd2d9bfb7dc7daf6f2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting the PDF's purpose is to distribute traffic to these external links, potentially for SEO manipulation or to serve as a lure for malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.ne
    • http://loaminoo.linkpc.net/1097095094097096/The-Stranger-Game-by-Cylin-Busby.pdf
    • http://loaminoo.linkpc.net/5095098096095094/The-Stranger-Game-by-Cylin-Busby.pdf
    • http://loaminoo.linkpc.net/4092091097096099/The-Nine-Lives-of-Jacob-Tibbs-by-Cylin-Busby.pdf
    • http://loaminoo.linkpc.net/1096091094091094/Rebels-Seed-by-F-M-Busby.pdf
    • http://loaminoo.linkpc.net/7095094096091094/New-Daughters-of-Africa-by-Margaret-Busby.pdf
    • http://loaminoo.linkpc.net/4096097095098091/Blink-of-an-Eye-by-Cath-Staincliffe.pdf
    • http://loaminoo.linkpc.net/2090095090097090/In-a-Blink-by-Kiki-Thorpe.pdf
    • http://loaminoo.linkpc.net/6093092093096/In-the-Blink-of-an-Eye-by-Walter-Murch.pdf
    • http://loaminoo.linkpc.net/3093093090097097/What-Are-You-Looking-At-150-Years-of-Modern-Art-in-the-Blink-of-an-Eye-by-Will-Gompertz.pdf
    • http://loaminoo.linkpc.net/5098099095090097/No-Time-To-Blink-by-Dina-Silver.pdf
    • http://loaminoo.linkpc.net/3094097098097099/In-the-Blink-of-an-Eye-StarCrossed-4-by-Reno-MacLeod.pdf
    • http://loaminoo.linkpc.net/4094094098092/Blink-and-You-Die-Ruby-Redfort-6-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/2092096095099098/Think-Why-Crucial-Decisions-Can-t-Be-Made-in-the-Blink-of-an-Eye-by-Michael-R-LeGault.pdf
    • http://loaminoo.linkpc.net/4098095095096/In-the-Blink-of-an-Eye-A-Perspective-on-Film-Editing-by-Walter-Murch.pdf
    • http://loaminoo.linkpc.net/1090099092096093099/In-the-Blink-of-an-Eye-My-Life-with-RSDS-by-Mary-Jane-Gonzales.pdf
    • http://loaminoo.linkpc.net/1090092097095091/A-Blink-of-the-Screen-Collected-Shorter-Fiction-by-Terry-Pratchett.pdf
    • http://loaminoo.linkpc.net/4094095095099092/Don-t-Blink-What-the-Little-Boy-Nobody-Expected-to-Live-Is-Teaching-the-World-about-Life-by-Brandon-Buell.pdf
    • http://loaminoo.linkpc.net/9094094093098099/What-Makes-You-Cough-Sneeze-Burp-Hiccup-Blink-Yawn-Sweat-and-Shiver-by-Jean-Stangl.pdf
    • http://loaminoo.linkpc.net/2097092091098098/Blink-The-Power-of-Thinking-Without-Thinking-by-Malcolm-Gladwell.pdf
    • http://loaminoo.linkpc.net/3099099097091092/Blink-The-Power-of-Thinking-Without-Thinking-by-Malcolm-Gladwell.pdf