Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1061172af68ff00…

MALICIOUS

PDF

17.9 KB Created: 2019-04-30 05:01:18 +01:00 Authoring application: mPDF 5.7
MD5: 1e3a2c8ca6c699cfbc5b6e0506ebc8f4 SHA-1: 5d16aa9b5ad799f746fbe3c1f286b7c136a1430f SHA-256: e1061172af68ff002d9811ed3621cc35dfd01050edf9f86f11a830104d2f7e18
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves appear to point to book titles and are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3099099098099093/Good-Night-Sleep-Tight-The-Sleep-Lady-s-Gentle-Guide-to-Helping-Your-Child-Go-to-Sleep-Stay-Asleep-and-Wake-Up-Happy-by-Kim-West.pdf
    • http://loaminoo.linkpc.net/1098095099090/The-Floppy-Sleep-Game-Book-A-Proven-4--Week-Plan-to-Get-Your-Child-to-Sleep-by-Patti-Teel.pdf
    • http://loaminoo.linkpc.net/4094097098093096/Why-We-Sleep-Unlocking-the-Power-of-Sleep-and-Dreams-by-Matthew-Walker.pdf
    • http://loaminoo.linkpc.net/3099094099097099/Sleep-Soundly-Every-Night-Feel-Fantastic-Every-Day-A-Doctor-s-Guide-to-Solving-Your-Sleep-Problems-by-Robert-S-Rosenberg.pdf
    • http://loaminoo.linkpc.net/3097095093090090/Stop-Losing-Sleep-Establish-Healthy-Sleep-Patterns-to-Improve-your-Health-and-Energy-by-Kyle-Richards.pdf
    • http://loaminoo.linkpc.net/3093098098090090/The-Sleep-Solution-why-your-sleep-is-broken-and-how-to-fix-it-by-W-Chris-Winter.pdf
    • http://loaminoo.linkpc.net/2099097090091093/Chasing-Adonis-by-Gina-Ardito.pdf
    • http://loaminoo.linkpc.net/9091093095097/Sleep-Baby-Sleep-by-Teri-Weidner.pdf
    • http://loaminoo.linkpc.net/5091099095090097/Sleep-Big-Bear-Sleep-by-Maureen-Wright.pdf
    • http://loaminoo.linkpc.net/8092091092092090/Venus-and-Adonis-1627-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/1096095092097097/The-Gardens-of-Adonis-Spices-in-Greek-Mythology---Second-Edition-by-Marcel-Detienne.pdf
    • http://loaminoo.linkpc.net/7090090094094098/Twelve-Hours-Sleep-by-Twelve-Weeks-Old-A-Step-By-Step-Plan-for-Baby-Sleep-Success-by-Suzy-Giordano.pdf
    • http://loaminoo.linkpc.net/6098097092090096/Before-I-Go-To-Sleep-by-S-J-Watson.pdf
    • http://loaminoo.linkpc.net/3090093093099091/Cry-Myself-to-Sleep-by-Joe-Peters.pdf
    • http://loaminoo.linkpc.net/7097097090099090/Before-I-Go-To-Sleep-by-S-J-Watson.pdf
    • http://loaminoo.linkpc.net/6091091097/We-Shall-Not-All-Sleep-by-Estep-Nagy.pdf
    • http://loaminoo.linkpc.net/4096092095094097/Before-We-Sleep-by-Jeffrey-Lent.pdf
    • http://loaminoo.linkpc.net/3099090096097090/Seriously-Just-Go-to-Sleep-by-Adam-Mansbach.pdf
    • http://loaminoo.linkpc.net/9092097098093/No-Go-Sleep-by-Kate-Feiffer.pdf
    • http://loaminoo.linkpc.net/4099093096099/Beyond-The-Wall-Of-Sleep-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/3093098098090090/The-Sleep-Solution-why-your-sleep-is-broken-and-how-to-fix-it-by-W-Chris-Wint