Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5c51281ccfe6e6a…

MALICIOUS

PDF

16.7 KB Created: 2019-04-30 08:50:39 +01:00 Authoring application: mPDF 5.7
MD5: c36598af2b1fdb1e60dbe0f936f3c13d SHA-1: 98fe2f8795136dd3a38d773d9eaed7da4d2b7df2 SHA-256: f5c51281ccfe6e6acfe2cd2888eba810d60795e2fee08dbe05a27b571ded8c6f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. While the specific URLs extracted were labeled as confirmed benign, the heuristic indicates a mass of external links, suggesting a potential for SEO manipulation or redirection to malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092093093098099/Arms-Wide-Open-A-Midwife-s-Journey-by-Patricia-Harman.pdf
    • http://loaminoo.linkpc.net/3095092099098090/The-Reluctant-Midwife-Hope-River-2-by-Patricia-Harman.pdf
    • http://loaminoo.linkpc.net/1099098099097099/Arms-Wide-Open-by-Tom-Winter.pdf
    • http://loaminoo.linkpc.net/6096099091096097/Wide-Open-My-Adventures-in-Polyamory-Open-Marriage-and-Loving-on-My-Own-Terms-by-Gracie-X.pdf
    • http://loaminoo.linkpc.net/1090095095091097099/Broken-Wide-Open-by-Susan-Griscom.pdf
    • http://loaminoo.linkpc.net/9097091098091099/Lucian-Freud-Eyes-Wide-Open-by-Phoebe-Hoban.pdf
    • http://loaminoo.linkpc.net/4097091096090097/Mouth-Wide-Open-A-Cook-And-His-Appetite-by-John-Thorne.pdf
    • http://loaminoo.linkpc.net/4092093098096095/Open-Wide-The-Freedom-Gates-A-Memoir-by-Dorothy-I-Height.pdf
    • http://loaminoo.linkpc.net/9099090095090/Wide-Open-Spaces-Beyond-Paint-by-Number-Christianity-by-Jim-Palmer.pdf
    • http://loaminoo.linkpc.net/1090098092099093090/Guerlain-Nude-Pussy-Close-Up---Big-Tits-and-Wide-Open-Legs-by-Bad-Girl.pdf
    • http://loaminoo.linkpc.net/2091093095093096/Mind-Wide-Open-Your-Brain-and-the-Neuroscience-of-Everyday-Life-by-Steven-Johnson.pdf
    • http://loaminoo.linkpc.net/1093098095094094/Aren-t-We-Sisters-The-Midwife-s-Daughter-2-by-Patricia-Ferguson.pdf
    • http://loaminoo.linkpc.net/2095098093092094/Texas-Wide-Open-Texas-Fever-1-by-K-C-Klein.pdf
    • http://loaminoo.linkpc.net/1091094099098098092/Empty-Hands-Open-Arms-The-Race-to-Save-Bonobos-in-the-Congo-and-Make-Conservation-Go-Viral-by-Deni-Ellis-B-chard.pdf
    • http://loaminoo.linkpc.net/6093095/The-Midwife-s-Revolt-The-Midwife-Series-1-by-Jodi-Daynard.pdf
    • http://loaminoo.linkpc.net/4093091092091090/The-Midwife-and-the-Assassin-Midwife-Mysteries-4-by-Sam-Thomas.pdf
    • http://loaminoo.linkpc.net/3092093091098098/The-Midwife-s-Tale-Midwife-Mysteries-1-by-Sam-Thomas.pdf
    • http://loaminoo.linkpc.net/1090091094093090090/All-the-Roads-Are-Open-The-Afghan-Journey-by-Annemarie-Schwarzenbach.pdf
    • http://loaminoo.linkpc.net/1090094098091099096/The-Wide-Wide-World-by-Susan-Bogert-Warner.pdf
    • http://loaminoo.linkpc.net/7093091098094091/The-Open-Road-The-Global-Journey-Of-The-Fourteenth-Dalai-Lama-by-Pico-Lyer.pdf
    • http://loaminoo.linkpc.net/2091093095093096/Mind-Wide-Open-