Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1afca7c0f8c4dbc…

MALICIOUS

PDF

21.5 KB Created: 2019-05-04 12:37:11 +01:00 Authoring application: mPDF 5.7
MD5: 2789cf721646502e2c737eea93bcbe4d SHA-1: b17e9f6cf0f299253d16a128a2e3e21cb0ea4d57 SHA-256: e1afca7c0f8c4dbcdf6ab57da6511616892b009aeef9829f151337c9913ead0e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier and contains a large number of embedded URLs, indicating a potential SEO poisoning or link farm attack. While no scripts were extracted, the sheer volume of links suggests a malicious intent to redirect users or manipulate search results. The primary attack pattern observed is the creation of a link farm within the PDF document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1092093091096094/Many-Many-Many-Gods-of-Hinduism-Turning-Believers-Into-Non-Believers-and-Non-Believers-Into-Believers-by-Swami-Achuthananda.pdf
    • http://loaminoo.linkpc.net/4094099095093092/Barefoot-in-White-Barefoot-Bay-Brides-Trilogy-1-Barefoot-Bay-Universe-8-by-Roxanne-St-Claire.pdf
    • http://loaminoo.linkpc.net/2096090093095092/Barefoot-in-Pearls-Barefoot-Bay-Brides-Trilogy-3-Barefoot-Bay-Universe-10-by-Roxanne-St-Claire.pdf
    • http://loaminoo.linkpc.net/1092093090093097/Barefoot-in-White-Barefoot-Bay-Brides-Trilogy-1-Barefoot-Bay-Universe-8-by-Roxanne-St-Claire.pdf
    • http://loaminoo.linkpc.net/3096095094092092/Barefoot-in-the-Sun-Barefoot-Bay-3-Barefoot-Bay-Universe-3-by-Roxanne-St-Claire.pdf
    • http://loaminoo.linkpc.net/2092092097094095/The-Barefoot-Billionaires-A-Barefoot-Bay-Boxed-Set-The-Billionaires-of-Barefoot-Bay-1-3-by-Roxanne-St-Claire.pdf
    • http://loaminoo.linkpc.net/4091097095091094/The-Barefoot-Book-of-Dance-Stories-Barefoot-Books-by-Jane-Yolen.pdf
    • http://loaminoo.linkpc.net/5099094094095097/Secrets-on-the-Sand-The-Billionaires-of-Barefoot-Bay-1-Barefoot-Bay-Universe-5-by-Roxanne-St-Claire.pdf
    • http://loaminoo.linkpc.net/4097091090096091/Somebody-s-Baby-by-Annie-Jones.pdf
    • http://loaminoo.linkpc.net/3096098092096092/Sister-Belles-by-Annie-Jones.pdf
    • http://loaminoo.linkpc.net/2095092099093/Home-to-Stay-by-Annie-Jones.pdf
    • http://loaminoo.linkpc.net/6095096094091094/A-Roaring-in-the-Blood-Remembering-Robert-F-Jones-by-Annie-Proulx.pdf
    • http://loaminoo.linkpc.net/4094093091098090/True-Believers-by-Maria-Zannini.pdf
    • http://loaminoo.linkpc.net/1098097091095091/Believers-A-Journey-Into-Evangelical-America-by-Jeffery-L-Sheler.pdf
    • http://loaminoo.linkpc.net/4093093092096099/Sayyida-Khadija-RA---Mother-of-the-believers-by-Abdul-Malik-Mujahid.pdf
    • http://loaminoo.linkpc.net/9094097098095095/The-Gifts-of-the-Holy-Spirit-to-Unbelievers-and-Believers-by-Clement-Read-Vaughan.pdf
    • http://loaminoo.linkpc.net/3093093092093097/Skeptics-and-True-Believers-The-Exhilarating-Connection-Between-Science-and-Spirituality-by-Chet-Raymo.pdf
    • http://loaminoo.linkpc.net/3090096091099095/Three-by-Annie-Dillard-Pilgrim-at-Tinker-Creek-An-American-Childhood-The-Writing-Life-by-Annie-Dillard.pdf
    • http://loaminoo.linkpc.net/4097095094098099/Annie-Moore-First-in-Line-for-America-Annie-Moore-1-by-Eithne-Loughrey.pdf
    • http://loaminoo.linkpc.net/5092096093093095/Photographs-Annie-Leibovitz-1970-1990-by-Annie-Leibovitz.pdf
    • http://loaminoo.linkpc.net