Malicious PDF — malware analysis report

Static analysis result for SHA-256 d21783d8786426a1…

MALICIOUS

PDF

21.7 KB Created: 2019-04-30 01:43:58 +01:00 Authoring application: mPDF 5.7
MD5: 0f703c82f62398158da9dd085c27fe81 SHA-1: 4caa470ac777b6c8a9f35811f0781d09ac03df9c SHA-256: d21783d8786426a19ce7214a87c21b40ba2620817de810826ab08a3eedc67862
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this file as malicious with high confidence. While the document body is heavily obfuscated, the presence of numerous links to a single domain suggests a link farm or redirection scheme, likely intended to drive traffic to malicious content or phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8096090096092094/Does-It-Really-Rain-Frogs-Questions-and-Answers-about-Planet-Earth-by-Thomas-Canavan-Jr-.pdf
    • http://loaminoo.linkpc.net/8096090096092096/Why-Do-Ice-Cubes-Float-Questions-and-Answers-about-the-Science-of-Everyday-Materials-by-Thomas-Canavan-Jr-.pdf
    • http://loaminoo.linkpc.net/8096090096092095/Why-Are-Black-Holes-Black-Questions-and-Answers-about-Space-by-Thomas-Canavan-Jr-.pdf
    • http://loaminoo.linkpc.net/3093092091092094/Concordex-of-the-Urantia-Book-The-Urantia-Book-is-the-Fifth-Epochal-to-our-planet-Urantia-It-accurately-answers-the-most-asked-questions-on-earth-by-Clyde-Bedell.pdf
    • http://loaminoo.linkpc.net/2099097099095098/Mystery-and-Crime-The-New-York-Public-Library-Book-of-Answers-Intriguing-and-Entertaining-Questions-and-Answers-About-the-Who-s-Who-and-Whats-s-by-Jay-Pearsall.pdf
    • http://loaminoo.linkpc.net/9090091098/Brief-Answers-to-the-Big-Questions-by-Stephen-Hawking.pdf
    • http://loaminoo.linkpc.net/3094094095097097/Questions-and-Answers-about-Weather-by-M-Jean-Craig.pdf
    • http://loaminoo.linkpc.net/6099099094092097/Essentials-of-NLP-150-Questions-amp-Answers-by-Shlomo-Vaknin.pdf
    • http://loaminoo.linkpc.net/4095093097094099/What-Do-You-think-of-Me-Why-Do-I-Care-Answers-to-the-Big-Questions-of-Life-by-Edward-T-Welch.pdf
    • http://loaminoo.linkpc.net/4095096092090/The-New-Answers-Book-1-Over-25-Questions-on-Creation-Evolution-and-the-Bible-by-Ken-Ham.pdf
    • http://loaminoo.linkpc.net/8091090093095/The-New-Answers-Book-4-Over-30-Questions-on-Evolution-Creation-and-the-Bible-by-Ken-Ham.pdf
    • http://loaminoo.linkpc.net/1091094099097096099/Multiple-Sclerosis-5th-Edition-The-Questions-You-Have-The-Answers-You-Need-by-Rosalind-C-Kalb.pdf
    • http://loaminoo.linkpc.net/9099095092096095/Asthma-Questions-You-Have-Answers-You-Need-by-Paula-Brisco-Dr-Robert-Youngson.pdf
    • http://loaminoo.linkpc.net/2095099092092094/Great-Answers-To-Tough-Interview-Questions-by-Martin-Yate.pdf
    • http://loaminoo.linkpc.net/1091093090093091091/The-250-Job-Interview-Questions-You-ll-Most-Likely-Be-Asked-and-the-Answers-That-Will-Get-You-Hired-by-Peter-Veruki.pdf
    • http://loaminoo.linkpc.net/7095093094097/A-Modern-Prophet-Answers-Your-Key-Questions-about-Life-by-Harold-Klemp.pdf
    • http://loaminoo.linkpc.net/5098098090092/What-If-Serious-Scientific-Answers-to-Absurd-Hypothetical-Questions-by-Randall-Munroe.pdf
    • http://loaminoo.linkpc.net/1090091091090/What-If-Serious-Scientific-Answers-to-Absurd-Hypothetical-Questions-by-Randall-Munroe.pdf
    • http://loaminoo.linkpc.net/7092094099091/Heaven-Biblical-Answers-to-Common-Questions-by-Randy-Alcorn.pdf
    • http://loaminoo.linkpc.net/8096090093099096/Doctor-Who-Salt-of-the-Earth-by-Trudi-Canavan.pdf
    • http://loaminoo.linkpc.net/2099097099095098/Mystery-and-Crime-The-New-York-Public-Library-Book-of-Answers-Intriguing-and-Entertaining-Questions-and-Answers-About-the-Who-s-Who-and-Whats-s-b