Malicious PDF — malware analysis report

Static analysis result for SHA-256 db81fc85ade9758c…

MALICIOUS

PDF

26.8 KB Created: 2019-05-02 04:52:12 +01:00 Authoring application: mPDF 5.7
MD5: 2a16a3776badac50483cb6a164b68b80 SHA-1: a04e916a9a6ea80f063d01efdab7f309771fe258 SHA-256: db81fc85ade9758c30a95202ca8cf4f6b304ef30866a795b36b4f2cf0996d77a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. This is indicative of a SEO poisoning or link-farming attack, likely intended to drive traffic to malicious or deceptive content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3098095096099094/The-Oxford-History-of-the-British-Empire-Volume-II-The-Eighteenth-Century-by-Peter-James-Marshall.pdf
    • http://loaminoo.linkpc.net/3098095096098099/The-Oxford-History-of-the-British-Empire-Volume-IV-The-Twentieth-Century-Twentieth-Century-Vol-4-by-Judith-M-Brown.pdf
    • http://loaminoo.linkpc.net/9094090091096093/Eighteenth-Century-British-Midwifery-Part-II-by-Pam-Lieske.pdf
    • http://loaminoo.linkpc.net/3099090092094097/The-Broadview-Anthology-of-British-Literature-Volume-6a-The-Twentieth-Century-and-Beyond-From-1900-to-Mid-Century-Volume-6a-The-Twentieth-Century-and-Beyond-From-1900-to-Mid-Century-by-Joseph-Laurence-Black.pdf
    • http://loaminoo.linkpc.net/5091092095099099/Captives-and-Voyagers-Black-Migrants-Across-the-Eighteenth-Century-British-Atlantic-World-by-Alexander-X-Byrd.pdf
    • http://loaminoo.linkpc.net/1091094097093093092/Torrid-Zones-Maternity-Sexuality-and-Empire-in-Eighteenth-Century-English-Narratives-by-Felicity-Nussbaum.pdf
    • http://loaminoo.linkpc.net/1091091099095091095/John-Law-A-Scottish-Adventurer-in-the-Eighteenth-Century-by-James-Buchan.pdf
    • http://loaminoo.linkpc.net/1091090094092095093/Strunk-s-Source-Readings-in-Music-History-The-Late-Eighteenth-Century-by-Wye-Allanbrook.pdf
    • http://loaminoo.linkpc.net/1097098090098094/The-Norton-Anthology-of-English-Literature-Volume-1-The-Middle-Ages-through-the-Restoration-amp-the-Eighteenth-Century-by-M-H-Abrams.pdf
    • http://loaminoo.linkpc.net/4090092094092091/Like-Hidden-Fire-The-Plot-to-Bring-Down-the-British-Empire-by-Peter-Hopkirk.pdf
    • http://loaminoo.linkpc.net/1091097092097095094/An-Empire-of-Regions-A-Brief-History-of-Colonial-British-America-by-Eric-Nellis.pdf
    • http://loaminoo.linkpc.net/9090096097093/The-Blood-Never-Dried-A-People-s-History-of-the-British-Empire-by-John-Newsinger.pdf
    • http://loaminoo.linkpc.net/1094091092091093/Oxford-History-of-Western-Music-6-Volume-Set-by-Richard-Taruskin.pdf
    • http://loaminoo.linkpc.net/4090091096092095/Demanding-the-Impossible-A-History-of-Anarchism-by-Peter-Marshall.pdf
    • http://loaminoo.linkpc.net/5096092098099/Century-of-Conflict-The-Struggle-Between-the-French-and-British-in-Colonial-America-Canadian-History-Series-2-by-Joseph-Lister-Rutledge.pdf
    • http://loaminoo.linkpc.net/4097095094099/A-Man-Called-Peter-The-Story-of-Peter-Marshall-by-Catherine-Marshall.pdf
    • http://loaminoo.linkpc.net/6092095091092092/A-Provincial-History-of-the-Ottoman-Empire-Cyprus-and-the-Eastern-Mediterranean-in-the-Nineteenth-Century-by-Marc-Aymes.pdf
    • http://loaminoo.linkpc.net/5099095099098099/The-Making-and-Unmaking-of-Empires-Britain-India-and-America-C-1750-1783-by-Peter-James-Marshall.pdf
    • http://loaminoo.linkpc.net/2093091098094/The-Triumphant-Empire-Thunder-Clouds-Gather-in-the-West-1763-1766-The-British-Empire-before-the-American-Revolution-10-by-Lawrence-Henry-Gipson.pdf
    • http://loaminoo.linkpc.net/4094098097098094/The-Ruin-of-the-Roman-Empire-A-New-History-by-James-J-O-39-Donnell.pdf
    • http://loaminoo.linkpc.net/5091092095099099/Captives-and-Voyagers-Black-Migrants-Across-the-Eighteenth-Century-British-Atlantic-World-by