Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef965f406cf9877c…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 20:30:52 +01:00 Authoring application: mPDF 5.7
MD5: ed28aca1b1b97aeafbe9f0a1542058f5 SHA-1: 8cd830bac76dbb9d0593c44bc538297d244e9141 SHA-256: ef965f406cf9877c09a45e7a281c338d186eca4b5ae339fa491369b9412d27d7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external resources, identified as a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a collection of URLs, likely for SEO spam or to host further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096094097095092/Sixty-Days-and-Counting-Science-in-the-Capital-3-by-Kim-Stanley-Robinson.pdf
    • http://loaminoo.linkpc.net/1095097090096091/Martian-Summer-Robot-Arms-Cowboy-Spacemen-and-My-90-Days-with-the-Phoenix-Mars-Mission-by-Andrew-Kessler.pdf
    • http://loaminoo.linkpc.net/1094090098090099/Counting-Heads-Counting-Heads-1-by-David-Marusek.pdf
    • http://loaminoo.linkpc.net/1096093096099095/The-Phoenix-Embryo-Seasons-of-the-Phoenix-1-by-Jeanne-Marcella.pdf
    • http://loaminoo.linkpc.net/1090098093090098/The-Birth-of-a-Phoenix-Phoenix-Chronicles-1-by-Candice-Snow.pdf
    • http://loaminoo.linkpc.net/4090093094091092/Search-for-the-Phoenix-Phoenix-Series-Book-2-by-Jim-Proctor.pdf
    • http://loaminoo.linkpc.net/3097090091093093/Secrets-in-Phoenix-Phoenix-Holt-1-by-Gabriella-Lepore.pdf
    • http://loaminoo.linkpc.net/3090099098095092/Phoenix-Descending-Curse-of-the-Phoenix-1-by-Dorothy-Dreyer.pdf
    • http://loaminoo.linkpc.net/4095096090097094/Dark-Phoenix-Phoenix-2-by-Elise-Faber.pdf
    • http://loaminoo.linkpc.net/7090099090092093/Phoenix-Awakens-The-Phoenix-1-by-Eliza-Nolan.pdf
    • http://loaminoo.linkpc.net/7090099090099091/Red-Phoenix-Burning-Red-Phoenix-2-by-Larry-Bond.pdf
    • http://loaminoo.linkpc.net/9091092095097/Phoenix-Wright-Ace-Attorney-Official-Casebook-Vol-1---The-Phoenix-Wright-Files-by-Kenji-Kuroda.pdf
    • http://loaminoo.linkpc.net/2098095098092090/Phoenix-Child-Phoenix-Child-1-by-Alica-McKenna-Johnson.pdf
    • http://loaminoo.linkpc.net/2095096093091094/The-Phoenix-Project-Series-Books-1-3-The-Phoenix-Project-1-3-by-M-R-Pritchard.pdf
    • http://loaminoo.linkpc.net/4095092093090095/Eleven-Days-An-Unexpected-Love-Days-Trilogy-1-by-Lora-Lindy.pdf
    • http://loaminoo.linkpc.net/1090095091096096092/Counting-On-You-by-J-C-Reed.pdf
    • http://loaminoo.linkpc.net/1095095097094095/Phoenix-Island-Phoenix-Island-1-by-John-Dixon.pdf
    • http://loaminoo.linkpc.net/1092092094094/Lakota-Legacy-Wolf-Dreamer-Cowboy-Days-And-Indian-Nights-Seven-Days-by-Madeline-Baker.pdf
    • http://loaminoo.linkpc.net/4096097091/Christmas-Days-12-Stories-and-12-Feasts-for-12-Days-by-Jeanette-Winterson.pdf
    • http://loaminoo.linkpc.net/1090095091097099093/The-Counting-Downers-by-A-J-Compton.pdf
    • http://loaminoo.linkpc.net/70900