Malicious PDF — malware analysis report

Static analysis result for SHA-256 d7a82f0bffc610d0…

MALICIOUS

PDF

21.2 KB Created: 2019-04-30 03:58:17 +01:00 Authoring application: mPDF 5.7
MD5: 02102a5e395b073d405b80cfbe09822b SHA-1: 0a0ad86d6a247d9c5295fccf54c469914da2a392 SHA-256: d7a82f0bffc610d003e21d87a5c3f68adb5b211fe0d08b14bf00a2cdc4bbd437
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO manipulation or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099096098099091/Incredible-Turtles-Fun-Animal-Books-For-Kids-With-Facts-amp-Incredible-Photos-Exploring-Our-Incredible-World-Series-1-by-Mark-Smith.pdf
    • http://loaminoo.linkpc.net/3091097098094099/Incredible-Snakes-Fun-Animal-Books-for-Kids-With-Facts-amp-Incredible-Photos-Exploring-Our-Incredible-World-Children-s-Book-Series-by-Mark-Smith.pdf
    • http://loaminoo.linkpc.net/4097091097099093/Weird-but-True-Food-300-Bite-size-Facts-About-Incredible-Edibles-by-National-Geographic-Kids.pdf
    • http://loaminoo.linkpc.net/1098090098090099/The-Incredible-Life-of-the-Sea-Turtle-by-Mark-Smith.pdf
    • http://loaminoo.linkpc.net/3091092095095093/Books-for-Kids-Jurassic-World-Kids-books-Ages-3-10-Dinosaur-Cartoon-Photos-For-Kids-by-Robot-J-.pdf
    • http://loaminoo.linkpc.net/2097095097093/Miss-Smith-s-Incredible-Storybook-by-Michael-Garland.pdf
    • http://loaminoo.linkpc.net/3098090090096096/The-Incredible-Hercules-Against-The-World-by-Greg-Pak.pdf
    • http://loaminoo.linkpc.net/3093093091095099/The-Incredible-Hulk-Stalker-from-the-Stars-Marvel-Novel-Series-2-by-Len-Wein.pdf
    • http://loaminoo.linkpc.net/7099092091099096/The-World-s-Most-Incredible-Stories-The-Best-of-Fortean-Times-by-Adam-Sisman.pdf
    • http://loaminoo.linkpc.net/4094097096091090/Mr-Darwin-s-Incredible-Shrinking-World-science-and-technology-in-1859-by-Peter-Macinnis.pdf
    • http://loaminoo.linkpc.net/4094091092091093/Maximize-Your-Potential-Grow-Your-Expertise-Take-Bold-Risks-amp-Build-an-Incredible-Career-The-99U-Book-Series-by-Jocelyn-K-Glei.pdf
    • http://loaminoo.linkpc.net/2095091092098093/Lost-in-Shangri-La-A-True-Story-of-Survival-Adventure-and-the-Most-Incredible-Rescue-Mission-of-World-War-II-by-Mitchell-Zuckoff.pdf
    • http://loaminoo.linkpc.net/2094095098094095/Don-t-Put-Me-In-Coach-My-Incredible-NCAA-Journey-from-the-End-of-the-Bench-to-the-End-of-the-Bench-by-Mark-Titus.pdf
    • http://loaminoo.linkpc.net/3096092098097095/Death-And-the-Incredible-Life-After-by-T-N-T-.pdf
    • http://loaminoo.linkpc.net/3094096093098098/Incredible-Hulk-Vol-1-181-by-Len-Wein.pdf
    • http://loaminoo.linkpc.net/1091091099093092091/Incredible-Football-Feats-by-Jim-Benagh.pdf
    • http://loaminoo.linkpc.net/1097093095094091/The-Incredible-Journey-by-Catherine-Martin.pdf
    • http://loaminoo.linkpc.net/5092093094092090/The-Incredible-Voyage-by-Tristan-Jones.pdf
    • http://loaminoo.linkpc.net/3099092096090098/The-Incredible-Edible-Toe-by-Asher-Jones.pdf
    • http://loaminoo.linkpc.net/1090095090099095/Incredible-Incas-by-Terry-Deary.pdf