Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6c498451fdfb08a…

MALICIOUS

PDF

17.1 KB Created: 2019-05-01 18:25:18 +01:00 Authoring application: mPDF 5.7
MD5: 311521616be3352e50864b2055f7b635 SHA-1: d8a174223cb1b41da0711d06d989e6f40d16f000 SHA-256: f6c498451fdfb08acd62ae8e6d7579274defb1d21497ebb1f097c656dbdc3126
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. While the specific URLs extracted appear benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for other malicious content. The ML classifier strongly supports this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096096097094099/Fashion-Zeitgeist-Trends-and-Cycles-in-the-Fashion-System-by-Barbara-Vinken.pdf
    • http://loaminoo.linkpc.net/4093092094094094/Crimes-of-Fashion-Three-Women-One-Fashion-Empire-Six-Claws-by-Jonathan-Soroff.pdf
    • http://loaminoo.linkpc.net/1090093097093091098/50s-Fashion-Vintage-Fashion-and-Beauty-Ads-by-Jim-Heimann.pdf
    • http://loaminoo.linkpc.net/6098093092095091/Paso-Robles-motels-Paso-Robles-lodging-Hotels-in-Paso-Robles-Paso-Robles-hotels-by-hiecentralcoast.pdf
    • http://loaminoo.linkpc.net/1091093090095099097/Historic-Hotels-of-Texas-A-Traveler-s-Guide-by-Liz-Carmack.pdf
    • http://loaminoo.linkpc.net/1094091098096091/Lost-Girls-and-Love-Hotels-by-Catherine-Hanrahan.pdf
    • http://loaminoo.linkpc.net/1091094090090095/Historic-Alabama-Hotels-and-Resorts-by-James-Sulzby.pdf
    • http://loaminoo.linkpc.net/6098093091093095/Chateaux-and-Manoirs-444-Hotels-in-France-by-Jens-Brandenburg.pdf
    • http://loaminoo.linkpc.net/1090090095090090095/Component-Database-Systems-by-Klaus-R-Dittrich.pdf
    • http://loaminoo.linkpc.net/2097099098099095/Murder-at-the-Inn-A-Criminal-History-of-Britain-s-Pubs-and-Hotels-by-James-Moore.pdf
    • http://loaminoo.linkpc.net/7093092091097098/Rivages-Hotels-of-Character-and-Charm-in-Spain-by-Fodor-39-s-Travel-Publications-Inc-.pdf
    • http://loaminoo.linkpc.net/1090090095090090098/Ein-Universelles-Konzept-Zum-Flexiblen-Informationsschutz-in-Und-Mit-Rechensystemen-by-K-R-Dittrich.pdf
    • http://loaminoo.linkpc.net/1090090094097098097/Haifische-in-der-Spree-DaF-Lernkrimis-A1-A2-mit-Audio-CD-by-Roland-Dittrich.pdf
    • http://loaminoo.linkpc.net/1090090094096097099/Murder-Mountain-CeeCee-Gallagher-1-by-Stacy-Dittrich.pdf
    • http://loaminoo.linkpc.net/6098093090094096/The-Devil-s-Closet-CeeCee-Gallagher-2-by-Stacy-Dittrich.pdf
    • http://loaminoo.linkpc.net/3092092095090097/The-West-End-Front-The-Wartime-Secrets-of-London-s-Grand-Hotels-by-Matthew-Sweet.pdf
    • http://loaminoo.linkpc.net/9092090093096095/Living-Downtown-The-History-of-Residential-Hotels-in-the-United-States-by-Paul-Groth.pdf
    • http://loaminoo.linkpc.net/1090090094096097096/Mary-Jane-s-Grave-CeeCee-Gallagher-3-by-Stacy-Dittrich.pdf
    • http://loaminoo.linkpc.net/1090093098090096093/Bibi-amp-Tina---Schatten-ber-dem-Martinshof-by-Markus-Dittrich.pdf
    • http://loaminoo.linkpc.net/1090090094099094092/Social-Work-with-Older-Adults-by-Kathleen-McInnis-Dittrich.pdf