Malicious PDF — malware analysis report

Static analysis result for SHA-256 d48e56246c034ec5…

MALICIOUS

PDF

15.5 KB Created: 2019-05-01 10:07:54 +01:00 Authoring application: mPDF 5.7
MD5: a7227e8af28c16831ae913732fe0e62a SHA-1: 83cab26788876362c78b0ece5ee04911e92d0b7a SHA-256: d48e56246c034ec54ce340d48afbb0aa25c3f87212f16bcb76a814836c3cc003
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external sites. While the specific URLs extracted were labeled as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3093097090099097/Black-Panther-Vol-2-A-Nation-Under-Our-Feet-Book-2-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/8096092099099093/Black-Panther-3-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/8096093090099098/Black-Panther-10-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/8096093090091091/Rise-of-the-Black-Panther-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/7094099094/Between-the-World-and-Me-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/9093096099097/Between-the-World-and-Me-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/5098095093090/Between-the-World-and-Me-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/2095096097094091/We-Were-Eight-Years-in-Power-An-American-Tragedy-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/3094090094092091/We-Were-Eight-Years-in-Power-An-American-Tragedy-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/6095098091/We-Were-Eight-Years-in-Power-An-American-Tragedy-by-Ta-Nehisi-Coates.pdf
    • http://loaminoo.linkpc.net/8096093090097096/Black-Panther-Who-Is-The-Black-Panther-Prose-Novel-by-Jesse-J-Holland.pdf
    • http://loaminoo.linkpc.net/3091090099093090/Out-of-Control-Taken-by-the-Panther-4-by-V-M-Black.pdf
    • http://loaminoo.linkpc.net/8096093090097090/Black-Panther-Vol-1-by-Jack-Kirby.pdf
    • http://loaminoo.linkpc.net/1094093094096092/Civil-War-Black-Panther-by-Reginald-Hudlin.pdf
    • http://loaminoo.linkpc.net/8096093090098097/Call-of-the-Black-Panther-by-Katarina-Claire-England-Ross.pdf
    • http://loaminoo.linkpc.net/3097093097096099/Black-Panther-Long-Live-the-King-1-by-Nnedi-Okorafor.pdf
    • http://loaminoo.linkpc.net/6099097099091093/The-Thaumaturge-Book-1---The-Calling-by-Peter-Coates.pdf
    • http://loaminoo.linkpc.net/1093091096093092/The-Assassination-of-Fred-Hampton-How-the-FBI-and-the-Chicago-Police-Murdered-a-Black-Panther-by-Jeffrey-Haas.pdf
    • http://loaminoo.linkpc.net/2098098093093095/Seize-the-Time-The-Story-of-the-Black-Panther-Party-and-Huey-P-Newton-by-Bobby-Seale.pdf
    • http://loaminoo.linkpc.net/4096097098090097/Dragon-Her-Feet-Honey-and-Fur-2-Council-of-Black-Dragons-1-by-Celia-Kyle.pdf
    • http://loaminoo.linkpc.net/6095098091/We-Were-Eight-Years-in-Power-An-American-Tragedy-by-Ta