Malicious PDF — malware analysis report

Static analysis result for SHA-256 f5c8b5ca6a7fb970…

MALICIOUS

PDF

26.2 KB Created: 2019-05-04 14:21:50 +01:00 Authoring application: mPDF 5.7
MD5: e1efcf809d3add04336758e73fe72e47 SHA-1: 5287098305aea7f53550b19f067e3d462fb855fe SHA-256: f5c8b5ca6a7fb970bbce5c809b8d4476b02c2a91c47b8fbe3ce66ab2661fb796
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external PDFs, identified as a link farm. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure and URL distribution suggest a malicious intent, likely for SEO poisoning or to drive traffic to malicious sites disguised as legitimate content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093090098095/A-Midwife-s-Tale-The-Life-of-Martha-Ballard-Based-on-Her-Diary-1785-1812-by-Laurel-Thatcher-Ulrich.pdf
    • http://loaminoo.linkpc.net/2096097098094095/Good-Wives-Image-and-Reality-in-the-Lives-of-Women-in-Northern-New-England-1650-1750-by-Laurel-Thatcher-Ulrich.pdf
    • http://loaminoo.linkpc.net/3092093091098098/The-Midwife-s-Tale-Midwife-Mysteries-1-by-Sam-Thomas.pdf
    • http://loaminoo.linkpc.net/3094090091097094/The-Harlot-s-Tale-Midwife-Mysteries-2-by-Sam-Thomas.pdf
    • http://loaminoo.linkpc.net/1095099098096098/The-Midwife-s-Tale-by-Gretchen-Moran-Laskas.pdf
    • http://loaminoo.linkpc.net/1091094097093097096/Tragedy-and-the-Philosophical-Life-A-Response-to-Martha-Nussbaum-by-Martha-C-Beck.pdf
    • http://loaminoo.linkpc.net/3094090091097092/The-Witch-Hunter-s-Tale-Midwife-Mysteries-3-by-Sam-Thomas.pdf
    • http://loaminoo.linkpc.net/5090090098092/Diary-of-a-Submissive-A-Modern-True-Tale-of-Sexual-Awakening-The-Diary-of-a-Submissive-1-by-Sophie-Morgan.pdf
    • http://loaminoo.linkpc.net/6093095/The-Midwife-s-Revolt-The-Midwife-Series-1-by-Jodi-Daynard.pdf
    • http://loaminoo.linkpc.net/6096095099098095/The-Moon-and-Sixpence-One-Man-s-Journey-Across-the-Field-of-Art-and-into-Its-Depths-Based-on-the-Life-of-Paul-Gauguin-Biographical-Novel-based-on-the-of-the-famous-French-painter-Paul-Gauguin-by-W-Somerset-Maugham.pdf
    • http://loaminoo.linkpc.net/4093091092091090/The-Midwife-and-the-Assassin-Midwife-Mysteries-4-by-Sam-Thomas.pdf
    • http://loaminoo.linkpc.net/1090094095095090090/The-Original-1812-Grimm-Fairy-Tales-A-New-Translation-of-the-1812-First-Edition-Kinder-und-Hausm-rchen-Childrens-and-Household-Tales-1812-Childrens-and-Household-Tales-Kinder-und-Hausm-rchen-by-Oliver-Loo.pdf
    • http://loaminoo.linkpc.net/3098097091092091/A-Not-So-Simple-Life-Diary-of-a-Teenage-Diary-Maya-1-by-Melody-Carlson.pdf
    • http://loaminoo.linkpc.net/8091099093097091/Miracles-of-Life-Shanghai-to-Shepperton-An-Autobiography-by-J-G-Ballard.pdf
    • http://loaminoo.linkpc.net/8090094097099/A-Widow-s-Tale-The-1884-1896-Diary-of-Helen-Mar-Kimball-Whitney-Life-Writings-of-Frontier-Women-Vol-6-Life-Writings-of-Frontier-Women-by-Helen-Mar-Whitney.pdf
    • http://loaminoo.linkpc.net/6096092093097097/Lust-for-Life-A-Novel-Based-on-the-Life-of-Vincent-Van-Gogh-by-Irving-Stone.pdf
    • http://loaminoo.linkpc.net/1092096097091098/Orlean-Puckett-The-Life-of-a-Mountain-Midwife-by-Karen-Cecil-Smith.pdf
    • http://loaminoo.linkpc.net/9095097099096093/Summary-and-Analysis-of-The-Handmaid-s-Tale-Based-on-the-Book-by-Margaret-Atwood-by-Worth-Books.pdf
    • http://loaminoo.linkpc.net/6091097091091098/The-Laurel-s-Kitchen-Bread-Book-A-Guide-to-Whole-Grain-Breadmaking-by-Laurel-Robertson.pdf
    • http://loaminoo.linkpc.net/7099091094099093/Exploring-the-Bismarck-The-Real-Life-Quest-to-Find-Hitler-s-Greatest-Battleship-by-Robert-D-Ballard.pdf