Malicious PDF — malware analysis report

Static analysis result for SHA-256 d387c9972649771f…

MALICIOUS

PDF

20.9 KB Created: 2019-04-30 05:04:32 +01:00 Authoring application: mPDF 5.7
MD5: 027df844b5e17ed498d24c8d3b7486f3 SHA-1: 0f6fb4984c0890c74d12ce6a4037dfed5bf0d597 SHA-256: d387c9972649771f53122544e32ffbca8ad362e007e3addbe999916f39a8348e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While the specific content of the linked documents appears benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3093093099099094/Beauty-Sick-How-the-Cultural-Obsession-with-Appearance-Hurts-Girls-and-Women-by-Renee-Engeln.pdf
    • http://loaminoo.linkpc.net/4094099098096095/Girls-Like-Us-Forty-Extraordinary-Women-Celebrate-Girlhood-in-Story-Poetry-and-Song-by-Gina-Ren-e-Misiroglu.pdf
    • http://loaminoo.linkpc.net/5090096090092094/Sick-and-Tired-of-Being-Sick-and-Tired-Black-Women-s-Health-Activism-in-America-1890-1950-by-Susan-L-Smith.pdf
    • http://loaminoo.linkpc.net/3095094095097092/Where-Bad-Girls-Go-to-Fall-Good-Girls-2-by-Holly-Renee.pdf
    • http://loaminoo.linkpc.net/1090095095091099091/Ingres-in-Fashion-Representations-of-Dress-and-Appearance-in-Ingress-Images-of-Women-by-Aileen-Ribeiro.pdf
    • http://loaminoo.linkpc.net/4094091097091095/Dead-Elvis-A-Chronicle-of-a-Cultural-Obsession-by-Greil-Marcus.pdf
    • http://loaminoo.linkpc.net/3096097094092092/Jesus-in-America-Personal-Savior-Cultural-Hero-National-Obsession-by-Richard-Wightman-Fox.pdf
    • http://loaminoo.linkpc.net/3090098096095097/So-Much-It-Hurts-So-Much-It-Hurts-1-by-Melanie-Dawn.pdf
    • http://loaminoo.linkpc.net/4091095091096/The-Orchid-Thief-A-True-Story-of-Beauty-and-Obsession-by-Susan-Orlean.pdf
    • http://loaminoo.linkpc.net/2094093097095093/Love-Hurts-The-Killing-of-Rose-Love-Hurts-1-by-Holly-Hood.pdf
    • http://loaminoo.linkpc.net/3093099096099095/Doing-Harm-The-Truth-About-How-Bad-Medicine-and-Lazy-Science-Leave-Women-Dismissed-Misdiagnosed-and-Sick-by-Maya-Dusenbery.pdf
    • http://loaminoo.linkpc.net/8092097090/Dead-Girls-Essays-on-Surviving-an-American-Obsession-by-Alice-Bolin.pdf
    • http://loaminoo.linkpc.net/5094096091/Where-Good-Girls-Go-To-Die-Good-Girls-1-by-Holly-Renee.pdf
    • http://loaminoo.linkpc.net/4094092094094096/Me-My-Hair-and-I-Twenty-seven-Women-Untangle-an-Obsession-by-Elizabeth-Benedict.pdf
    • http://loaminoo.linkpc.net/3095093099096096/Beauty-Tips-For-Girls-by-Margaret-Montgomery.pdf
    • http://loaminoo.linkpc.net/2095099093091098/21-Teen-Devotionals-For-Girls-True-Beauty-Books-by-Shelley-Hitz.pdf
    • http://loaminoo.linkpc.net/8094091091090099/Francophone-Women-Writers-of-Africa-and-the-Caribbean-by-Renee-Larrier.pdf
    • http://loaminoo.linkpc.net/7092092090095097/Gender-Modernity-Indian-Delights-The-Women-s-Cultural-Group-of-Durban-1954-2010-by-Goolam-Vahed.pdf
    • http://loaminoo.linkpc.net/4092092097091094/Lives-of-Girls-and-Women-by-Alice-Munro.pdf
    • http://loaminoo.linkpc.net/4097098096092094/Face-Value-The-Hidden-Ways-Beauty-Shapes-Women-s-Lives-by-Autumn-Whitefield-Madrano.pdf
    • http://loaminoo.linkpc.net/1090095095091099091/Ingres-in-Fashion-Representations