Malicious PDF — malware analysis report

Static analysis result for SHA-256 f4e0ea4af68193bf…

MALICIOUS

PDF

22.1 KB Created: 2019-05-03 16:54:15 +01:00 Authoring application: mPDF 5.7
MD5: 23875ef2541c3d2f9194592ef9efbbd3 SHA-1: 175e9bb1d1161ebecf372d4ad73601ed90e47d4d SHA-256: f4e0ea4af68193bf79876a80f1361a1a946e00c08a50883158fae2d8ff3b5330
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to other PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly flagged this file as malicious. While the specific URLs appear to link to benign content, the sheer volume and structure suggest a link farm designed to obscure malicious intent or distribute further payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4094090091093096/Bananas-in-My-Ears-A-Collection-of-Nonsense-Stories-Poems-Riddles-amp-Rhymes-by-Michael-Rosen.pdf
    • http://loaminoo.linkpc.net/4095099098098096/The-Nation-s-Favourite-Poems-of-Remembrance-by-Michael-Rosen.pdf
    • http://loaminoo.linkpc.net/1091097094095091094/Riddles-Riddles-Riddles-Presented-by-Dennis-the-Menace-by-Joseph-Lemming.pdf
    • http://loaminoo.linkpc.net/4098099091094095/From-the-Heart-A-Collection-of-Poems-and-Stories-Memories-3-by-Sue-Julsen.pdf
    • http://loaminoo.linkpc.net/1093096095095099/Winnie-the-Pooh-The-Complete-Collection-of-Stories-and-Poems-by-A-A-Milne.pdf
    • http://loaminoo.linkpc.net/9096092095096/Michael-Rosen-s-Sad-Book-by-Michael-Rosen.pdf
    • http://loaminoo.linkpc.net/9097094090099/The-Earth-is-a-Floating-Sphere-A-Care-Free-Collection-of-Poems-and-Stories-by-Casey-Sean-Harmon.pdf
    • http://loaminoo.linkpc.net/4096090098099097/Garden-Hopping-A-collection-of-short-stories-by-Michael-Diack.pdf
    • http://loaminoo.linkpc.net/3091091098094090/Swimming-to-the-Moon-A-Collection-of-Rhymes-Without-Reason-by-Jeff-McMahon.pdf
    • http://loaminoo.linkpc.net/3099092098094092/Come-Hither-A-Family-Treasury-of-Best-Loved-Rhymes-and-Poems-for-Children-by-Walter-de-la-Mare.pdf
    • http://loaminoo.linkpc.net/3091093093091094/Early-Reading-Challenge-10-Bundle-with-15-stories-Beginner-readers-Adventure-Animal-stories-Teach-Values-Book-Funny-free-story-prime-Rhymes-Fantasy-Education-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3096090096098091/An-Elven-Game-of-Rhymes-Book-Two-of-the-Magical-Poems-of-Zardoa-Silverstar-by-The-Silver-Elves.pdf
    • http://loaminoo.linkpc.net/9096097092099/No-Nonsense-Guide-to-Cholesterol-Medications-Informed-Consent-and-Statin-Drugs-No-Nonsense-Guides-Book-2-by-Moira-Dolan.pdf
    • http://loaminoo.linkpc.net/2093092095094099/Everybody-Here-by-Michael-Rosen.pdf
    • http://loaminoo.linkpc.net/2092093090094096/Poems-Past-A-Collection-of-Poems-from-Years-Gone-by-by-Chanctetinyea-J-J-Ouellette.pdf
    • http://loaminoo.linkpc.net/6098094094090098/Tiny-Little-Fly-by-Michael-Rosen.pdf
    • http://loaminoo.linkpc.net/4099094099098094/The-Company-Of-Dogs-by-Michael-J-Rosen.pdf
    • http://loaminoo.linkpc.net/7098096092091099/Audio-Cd-And-3-Board-Books-Complete-Collection-Of-32-Arabic-Rhymes-This-Is-The-Way-Fish-Swim-Tasseh-Tarantaseh-My-Turtle-s-Name-Is-Nahla-by-Taghreed-A-Najjar.pdf
    • http://loaminoo.linkpc.net/1090092099092094097/Mirth-of-a-Nation-The-Best-Contemporary-Humor-by-Michael-J-Rosen.pdf
    • http://loaminoo.linkpc.net/5092097095096091/The-Kingfisher-Book-of-Children-s-Poetry-by-Michael-J-Rosen.pdf
    • http://loaminoo.linkpc.net/4096090098099097/Garden-Hopping-A-co