Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec168f090e0bd867…

MALICIOUS

PDF

15.6 KB Created: 2019-05-04 14:20:40 +01:00 Authoring application: mPDF 5.7
MD5: dcb68f562e7b0d0412352cef381e54e7 SHA-1: f20299e0c0de63338167a71ddf438ef6834ce94a SHA-256: ec168f090e0bd867591e00b9718b5ba2ec1b5092343baa703e9b3d005b54c7ef
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted were classified as benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to serve as a landing page for further malicious activity. The ML_NYX_PDF_MALICIOUS classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097091097091091/Sodom-A-Nation-On-Its-Knees-The-Search-for-the-Righteous-1-by-Pam-Funke.pdf
    • http://loaminoo.linkpc.net/7097091098093094/Cornelia-Funke-Picture-Books-Set-by-Cornelia-Funke.pdf
    • http://loaminoo.linkpc.net/3096096098090097/Sodom-Had-No-Bible-by-Leonard-Ravenhill.pdf
    • http://loaminoo.linkpc.net/2099092097091092/120-Days-of-Sodom-by-Marquis-de-Sade.pdf
    • http://loaminoo.linkpc.net/7091090097098/Shock-of-Gray-The-Aging-of-the-World-s-Population-and-How-it-Pits-Young-Against-Old-Child-Against-Parent-Worker-Against-Boss-Company-Against-Rival-and-Nation-Against-Nation-by-Ted-C-Fishman.pdf
    • http://loaminoo.linkpc.net/1097090091094097/Sodom-and-the-Phoenix-Virtual-Seduction-2-by-Ann-Mayburn.pdf
    • http://loaminoo.linkpc.net/7097098097090097/The-Protocols-of-the-Elders-of-Sodom-and-Other-Essays-by-Tariq-Ali.pdf
    • http://loaminoo.linkpc.net/2098091093095096/Sodom-and-Detroit-Virtual-Seduction-1-by-Ann-Mayburn.pdf
    • http://loaminoo.linkpc.net/1095095096093094/The-Sodom-and-Gomorrah-Business-by-Barry-N-Malzberg.pdf
    • http://loaminoo.linkpc.net/1090098092095094/Righteous-by-Kim-Lehman.pdf
    • http://loaminoo.linkpc.net/5093091092092090/Righteous-by-Kim-Lehman.pdf
    • http://loaminoo.linkpc.net/5095098096090091/The-Righteous-by-Michael-Wallace.pdf
    • http://loaminoo.linkpc.net/1090094093098095095/Becoming-of-the-Righteous-by-Joshua-Felsen.pdf
    • http://loaminoo.linkpc.net/1094097098092094/On-My-Knees-by-Ciana-Stone.pdf
    • http://loaminoo.linkpc.net/4095094091094097/Vampire-Lesbians-of-Sodom-and-Sleeping-Beauty-or-Coma-by-Charles-Busch.pdf
    • http://loaminoo.linkpc.net/9096094096098096/Die-Priesterin-von-Sodom-Eine-erotische-BDSM-Fantasie-by-Seth-Daniels.pdf
    • http://loaminoo.linkpc.net/7095097097091/The-Sleep-of-the-Righteous-by-Wolfgang-Hilbig.pdf
    • http://loaminoo.linkpc.net/4096090093095098/Abraham-the-Righteous-by-Reyaz-Nadeem.pdf
    • http://loaminoo.linkpc.net/5091091096090/Standing-on-My-Knees-by-John-Olive.pdf
    • http://loaminoo.linkpc.net/2094093091098093/Fall-on-Your-Knees-by-Ann-Marie-MacDonald.pdf
    • http://loaminoo.linkpc.net/1095095096093094/The-Sodom-and-Gomorrah-Bu