Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6d179eb970f4c46…

MALICIOUS

PDF

15.9 KB Created: 2019-05-01 23:37:51 +01:00 Authoring application: mPDF 5.7
MD5: e45034a426ce2c8fd3127116a9e55f17 SHA-1: 1e36d033c93d66ea67997c08e4187fb2707c3290 SHA-256: f6d179eb970f4c46712e0d8c9e68852c95a2eb7377a1209cf1fc7f7f03f0a6f7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to act as a landing page for further malicious activity. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7094090094090094/Therapeutics-of-Cholera-Cholera-Asiatica-by-P-C-Majumda-R.pdf
    • http://loaminoo.linkpc.net/9093093090099/The-Keya-Quests-The-Battle-for-Shivenridge-by-Glenn-Skinner.pdf
    • http://loaminoo.linkpc.net/8093099099096098/Animal-Toxins-Facts-And-Protocols-by-Herv-Rochat.pdf
    • http://loaminoo.linkpc.net/4090098099093099/A-New-World-by-Amit-Chaudhuri.pdf
    • http://loaminoo.linkpc.net/1094097093094092/The-Immortals-by-Amit-Chaudhuri.pdf
    • http://loaminoo.linkpc.net/3094093093091098/The-Heart-of-India-by-Nirad-C-Chaudhuri.pdf
    • http://loaminoo.linkpc.net/3094092094090099/Physics-of-God-Universe-Humankind-and-Peace-in-Family-by-Tapan-K-Chaudhuri.pdf
    • http://loaminoo.linkpc.net/4090098099095094/The-Vintage-Book-of-Modern-Indian-Literature-by-Amit-Chaudhuri.pdf
    • http://loaminoo.linkpc.net/9096095098090/Deadly-Toxins-of-Unhealthy-Churches-A-survivor-s-testimony-of-hope-and-triumph-amidst-the-turmoil-and-trauma-of-spiritual-abuse-by-Mike-Case.pdf
    • http://loaminoo.linkpc.net/7094090092096099/Cholera-by-E-Madoroba.pdf
    • http://loaminoo.linkpc.net/7094090092096093/Therapeutics-of-Cholera-by-P-C-Majumdar.pdf
    • http://loaminoo.linkpc.net/7094090090092099/Cholera-by-William-Coleman.pdf
    • http://loaminoo.linkpc.net/7094090090092095/Cholera-by-Diane-Bailey.pdf
    • http://loaminoo.linkpc.net/3095095099094092/The-Food-Babe-Way-Break-Free-from-the-Hidden-Toxins-in-Your-Food-and-Lose-Weight-Look-Years-Younger-and-Get-Healthy-in-Just-21-Days-by-Vani-Hari.pdf
    • http://loaminoo.linkpc.net/7094090094099096/The-Cholera-Problem-by-Oscar-Felsenfeld.pdf
    • http://loaminoo.linkpc.net/7094090094099097/A-Treatise-on-Cholera-by-Nathanael-Alcock.pdf
    • http://loaminoo.linkpc.net/7094090092096095/The-Treasure-Digital-by-Yogesh-Cholera.pdf
    • http://loaminoo.linkpc.net/7094090094099094/The-Epidemical-Cholera-by-Reginald-Orton.pdf
    • http://loaminoo.linkpc.net/7094090094091096/Smallpox-Cholera-by-Vasile-Tudor.pdf
    • http://loaminoo.linkpc.net/7094090094090099/Annals-of-Cholera-by-John-MacPherson.pdf