Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef301cde12d28c7c…

MALICIOUS

PDF

19.0 KB Created: 2019-04-30 02:50:08 +01:00 Authoring application: mPDF 5.7
MD5: de676ec9fa2f38c9725a61813b7c6a3f SHA-1: 06422eeba01973c5cd1b560f577538b1ec39c702 SHA-256: ef301cde12d28c7c0d50e06866a7e280aabb4b42bf2f186d657daedd14039cc7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO manipulation tactic. While the specific URLs extracted were labeled as confirmed_benign, the sheer volume and the ML classifier's high confidence indicate a malicious intent, likely to direct users to malicious sites or to manipulate search engine rankings. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4095095096091093/One-Good-Catch-A-Maguire-s-Corner-novel-by-Heather-M-Gardner.pdf
    • http://loaminoo.linkpc.net/5094095091095095/Maguire-s-Corner-by-Heather-M-Gardner.pdf
    • http://loaminoo.linkpc.net/2090098098095093/Catch-Me-Detective-D-D-Warren-6-by-Lisa-Gardner.pdf
    • http://loaminoo.linkpc.net/6094096090094/Catch-Me-Detective-D-D-Warren-6-by-Lisa-Gardner.pdf
    • http://loaminoo.linkpc.net/4093096095098096/How-to-Catch-a-Frog-And-Other-Stories-of-Family-Love-Dysfunction-Survival-and-DIY-by-Heather-Ross.pdf
    • http://loaminoo.linkpc.net/8095094097092097/Good-Work-When-Excellence-and-Ethics-Meet-by-Howard-Gardner.pdf
    • http://loaminoo.linkpc.net/1091092094098096093/Strangely-Incredibly-Good-Strangely-Incredibly-Good-1-by-Heather-Grace-Stewart.pdf
    • http://loaminoo.linkpc.net/4092090096094091/Remarkably-Great-Strangely-Incredibly-Good-2-by-Heather-Grace-Stewart.pdf
    • http://loaminoo.linkpc.net/3095098095098091/Find-the-Good-Unexpected-Life-Lessons-from-a-Small-Town-Obituary-Writer-by-Heather-Lende.pdf
    • http://loaminoo.linkpc.net/3099099092094098/Take-Good-Care-of-the-Garden-and-the-Dogs-Family-Friendships-and-Faith-in-Small-Town-Alaska-by-Heather-Lende.pdf
    • http://loaminoo.linkpc.net/6098091099091098/WRESTLING-Catch-As-Catch-Can-Style---23-Illustrated-Wrestling-Moves-by-Edward-Hitchcock-Jr-.pdf
    • http://loaminoo.linkpc.net/1091093091093099094/Gardner-s-Art-Through-the-Ages-Vol-1-Chapters-1-18-by-Helen-Gardner.pdf
    • http://loaminoo.linkpc.net/1091097094090090090/Catch-as-Catch-by-Rob-Budde.pdf
    • http://loaminoo.linkpc.net/3093094099093091/Jennie-s-Tiger-A-Woman-s-Pioneering-Stand-in-an-Untamed-Corner-of-Washington-State-A-Woman-s-Pioneering-Stand-in-an-Untamed-Corner-O-by-Eva-Gayle-Six.pdf
    • http://loaminoo.linkpc.net/2097092097091093/How-To-Catch-A-Billionaire-How-To-Catch-A-Billionaire-1-3-by-Helen-Cooper.pdf
    • http://loaminoo.linkpc.net/1097097095099090/To-Catch-A-Marlin-To-Catch-A-Marlin-1-by-T-K-Toppin.pdf
    • http://loaminoo.linkpc.net/2090096095092090/Thank-You-for-Riding-by-Meg-Maguire.pdf
    • http://loaminoo.linkpc.net/1090097092093098094/The-Good-Life-and-the-Greater-Good-in-a-Global-Context-by-Laura-Savu-Walker.pdf
    • http://loaminoo.linkpc.net/4099099092094095/Educate-Girls-Around-The-World-Good-People-Doing-Good-Work-by-Shay-Spivey.pdf
    • http://loaminoo.linkpc.net/4090091096094/The-Good-The-Bad-And-The-Bullied-The-Good-Girl-s-Bad-Boys-1-by-Rubix-Cube-89201.pdf
    • http://loaminoo.linkpc.net/3095098095098091/Find-the-Good-Unex