Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa4a9eba52315525…

MALICIOUS

PDF

16.5 KB Created: 2019-04-30 04:30:08 +01:00 Authoring application: mPDF 5.7
MD5: f8c17deb3efb57a46aa340cc381a939e SHA-1: 269abb9492e35935a9107c1ef469ba446930e988 SHA-256: fa4a9eba52315525abc07819c80b48fd8fed821c6b7e950d3860b01b4b749ad3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF was flagged by a critical heuristic for containing a mass external PDF link farm, with 21 numeric-slug SEO links. The ML classifier also strongly indicated maliciousness. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely to drive traffic to potentially compromised or malicious sites disguised as book downloads. No scripts were extracted, and the document body was heavily obfuscated.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6095090099098092/All-New-Invaders-Vol-1-Gods-and-Soldiers-by-James-Robinson.pdf
    • http://loaminoo.linkpc.net/1090098094098091091/Take-the-Darkness-and-Give-us-the-Light-Soldiers-and-Gods-2-by-Julius-Schenk.pdf
    • http://loaminoo.linkpc.net/2090095097094091/Take-the-Body-And-Give-Me-The-Rest-Soldiers-and-Gods-1-by-Julius-Schenk.pdf
    • http://loaminoo.linkpc.net/6095090098096098/Invaders-The-Chronowarp-Invaders-Series-Book-2-by-Vaughn-Heppner.pdf
    • http://loaminoo.linkpc.net/1091094096094099/The-Ghost-Soldiers-by-James-Tate.pdf
    • http://loaminoo.linkpc.net/9098097093099097/World-War-2-Waffen-SS-Soldiers---Testimonies-of-German-SS-Soldiers---2nd-Edition-World-War-2-WW2-WWII-German-Soldiers-by-Oliver-Mayer.pdf
    • http://loaminoo.linkpc.net/2095096095096092/Where-Have-All-the-Soldiers-Gone-The-Transformation-of-Modern-Europe-by-James-J-Sheehan.pdf
    • http://loaminoo.linkpc.net/6095090099098090/Invaders-of-the-Rokujouma-Volume-3-Invaders-of-the-Rokujouma-3-by-Takehaya.pdf
    • http://loaminoo.linkpc.net/8090099097093099/Unlikely-Soldiers-Civvy-to-Squaddie-Unlikely-Soldiers-1-by-Deb-McEwan.pdf
    • http://loaminoo.linkpc.net/3090095098093099/He-Man-and-the-Masters-of-the-Universe-Vol-1-by-James-Robinson.pdf
    • http://loaminoo.linkpc.net/2099098090090098/Gods-of-The-Nowhere-A-Novel-of-Halloween-by-James-Tipper.pdf
    • http://loaminoo.linkpc.net/3095092091097090/Rain-Gods-Hackberry-Holland-2-by-James-Lee-Burke.pdf
    • http://loaminoo.linkpc.net/4098094095095/Rain-Gods-Hackberry-Holland-2-by-James-Lee-Burke.pdf
    • http://loaminoo.linkpc.net/7094093095090099/Ye-Great-and-General-Courte-in-Collonie-Times-by-James-Robinson-Newhall.pdf
    • http://loaminoo.linkpc.net/1091090096098098096/James-Wyatt-1746-1813-Architect-to-George-III-by-John-Martin-Robinson.pdf
    • http://loaminoo.linkpc.net/4098098092098097/Gods-of-Fire-and-Thunder-Book-of-the-Gods-5-by-Fred-Saberhagen.pdf
    • http://loaminoo.linkpc.net/2099095098097094/Heart-of-the-Gods-Servant-of-the-Gods-2-by-Valerie-Douglas.pdf
    • http://loaminoo.linkpc.net/3091099098096092/Oh-My-Gods-A-Look-It-Up-Guide-to-the-Gods-of-Mythology-by-Megan-E-Bryant.pdf
    • http://loaminoo.linkpc.net/3091094098098093/In-the-Shadow-of-the-Gods-Bound-Gods-1-by-Rachel-Dunne.pdf
    • http://loaminoo.linkpc.net/5097096097094/The-Silent-Soldiers-The-Silent-Soldiers-1-by-Travis-Stinnett.pdf
    • http://loaminoo.linkpc.net/8090099097093099/Unlikely-Soldiers-Civvy-to-Squadd