Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9e2526c595feb68…

MALICIOUS

PDF

13.6 KB Created: 2019-04-30 05:17:28 +01:00 Authoring application: mPDF 5.7
MD5: 9e59a73925ab90860bf34d9145b631a8 SHA-1: 3e85ca7a1d427f968ffdcf68a4694cc61dfee746 SHA-256: e9e2526c595feb68ca734f5595508ff0cb2fe45e074c29f5b61f64bdf9156c5d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to serve as a distribution point for further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096099093095/The-Deep-Blue-Alibi-Solomon-vs-Lord-2-by-Paul-Levine.pdf
    • http://loaminoo.linkpc.net/1099096099091090/Solomon-vs-Lord-Solomon-vs-Lord-1-by-Paul-Levine.pdf
    • http://loaminoo.linkpc.net/9091091099092098/Elements-by-Solomon-Deep.pdf
    • http://loaminoo.linkpc.net/1097094094094091/Deep-Blue-Blue-1-by-Jules-Barnard.pdf
    • http://loaminoo.linkpc.net/2098095092096094/The-Blue-Notebook-by-James-A-Levine.pdf
    • http://loaminoo.linkpc.net/2092098096092096/Blue-Diablo-Corine-Solomon-1-by-Ann-Aguirre.pdf
    • http://loaminoo.linkpc.net/3096095091096095/Blue-Diablo-Corine-Solomon-1-by-Ann-Aguirre.pdf
    • http://loaminoo.linkpc.net/5098094099096096/9-Scorpions-by-Paul-Levine.pdf
    • http://loaminoo.linkpc.net/3091096094095097/THE-ROAD-TO-HELL-by-Paul-Levine.pdf
    • http://loaminoo.linkpc.net/1093090093/Bum-Rap-Jake-Lassiter-10-by-Paul-Levine.pdf
    • http://loaminoo.linkpc.net/8091090097096097/Tr-sors-sanglants-by-Paul-Levine.pdf
    • http://loaminoo.linkpc.net/1097097099095090/Fool-Me-Twice-Jake-Lassiter-6-by-Paul-Levine.pdf
    • http://loaminoo.linkpc.net/1097090098094098/Words-in-Deep-Blue-by-Cath-Crowley.pdf
    • http://loaminoo.linkpc.net/2097090099099090/Words-in-Deep-Blue-by-Cath-Crowley.pdf
    • http://loaminoo.linkpc.net/3098094093095095/Deep-Blue-Doc-Ford-23-by-Randy-Wayne-White.pdf
    • http://loaminoo.linkpc.net/2091090094098098/Deep-Blue-Eyes-and-Other-Lies-by-Janette-Rallison.pdf
    • http://loaminoo.linkpc.net/8099093095097/Deep-Blue-Waterfire-Saga-1-by-Jennifer-Donnelly.pdf
    • http://loaminoo.linkpc.net/3091090093090098/At-Home-Between-the-Devil-and-the-Deep-Blue-Sky-by-KoKo-Nervelli.pdf
    • http://loaminoo.linkpc.net/2094093094099096/Deep-Blue-Eyes-on-the-Greek-Isles-by-Dimitri-Sarantis.pdf
    • http://loaminoo.linkpc.net/3094092095090095/The-Deep-Blue-Good-by-Travis-McGee-1-by-John-D-MacDonald.pdf