Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9ec1432c7b336b1…

MALICIOUS

PDF

21.2 KB Created: 2019-05-02 01:25:01 +01:00 Authoring application: mPDF 5.7
MD5: d79ef4b909f97b2ceec6f2e0cd4a37cf SHA-1: 5c8aced9e5cdf4fe3c2ac9273f4e3df2685389d0 SHA-256: e9ec1432c7b336b18caeb080b79be9199b84a82efc65ced74bdeb81b9be4ffae
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1204.002 Malicious Link: Malicious File

The PDF contains a large number of embedded links to external PDF files, all hosted on the same domain. This pattern is indicative of SEO manipulation or a link farm designed to distribute malicious content or redirect users to phishing sites. The ML classifier strongly supports the malicious verdict. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5096098093096099/Meridian-by-Nancy-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093091090/Continental-Drift-by-Nancy-Gaffield.pdf
    • http://loaminoo.linkpc.net/9093095093099096/Hiroshige-s-Tokaido-in-Prints-and-Poetry-by-Reiko-Chiba.pdf
    • http://loaminoo.linkpc.net/1093095099092/The-Ghost-in-the-Tokaido-Inn-Samurai-Detective-1-by-Dorothy-Hoobler.pdf
    • http://loaminoo.linkpc.net/5096098092099097/Slow-Down-by-John-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093096092/Action-of-sunlight-on-glass-by-Thomas-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093096095/The-Action-of-Sunlight-on-Glass-by-Thomas-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093097095/The-Past-Revealed-A-Series-of-Revelations-Concerning-the-Early-Scriptures-by-E-C-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093090092/The-Haitian-Declaration-of-Independence-Creation-Context-and-Legacy-by-Julia-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098092099099/Haitian-Connections-in-the-Atlantic-World-Recognition-After-Revolution-by-Julia-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093090099/Constructing-Modern-Canada-Readings-In-Post-Confederation-History-by-Chad-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093097092/A-Series-of-Meditations-on-the-Ethical-and-Psychical-Relation-of-Spirit-to-the-Human-Organism-by-Erastus-C-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093097091/The-Past-Revealed-A-Series-Of-Revelations-Concerning-The-Early-Scriptures-1905-by-Erastus-Celley-Gaffield.pdf
    • http://loaminoo.linkpc.net/7093099099098/Where-s-Nancy-Nancy-Drew-Girl-Detective-Super-Mystery-1-by-Carolyn-Keene.pdf
    • http://loaminoo.linkpc.net/5096098093097090/The-Canadian-Distinctiveness-Into-the-Xxist-Century---La-Distinction-Canadienne-Au-Tournant-Du-Xxie-Siecle-by-Chad-Gaffield.pdf
    • http://loaminoo.linkpc.net/5096098093097094/A-Celestial-Message-A-Relation-of-the-Observations-and-Experiences-of-a-Philosopher-and-Poet-in-the-Spirit-World-by-Erastus-C-Gaffield.pdf
    • http://loaminoo.linkpc.net/2090093098094099/In-Search-of-Captain-Zero-A-Surfer-s-Road-Trip-beyond-the-End-of-the-Road-by-Allan-C-Weisbecker.pdf
    • http://loaminoo.linkpc.net/4090097090095/In-Search-of-Captain-Zero-A-Surfer-s-Road-Trip-Beyond-the-End-of-the-Road-by-Allan-C-Weisbecker.pdf
    • http://loaminoo.linkpc.net/9097090092094/One-for-the-Road-Road-1-by-Elise-K-Ackers.pdf
    • http://loaminoo.linkpc.net/9099092096093/It-s-a-Mad-Mad-Mad-Mad-Trip-On-the-Road-of-the-Longest-Two-Week-Family-Road-Trip-in-History-by-Kevin-J-Shay.pdf
    • http://loaminoo.linkpc.net/5096098092099099/Haitian-Connections-in-the-Atlantic-World-Recognition-After-Revolution-by-Julia-Gaffie