Malicious PDF — malware analysis report

Static analysis result for SHA-256 04ae024804f34812…

MALICIOUS

PDF

15.7 KB Created: 2019-05-02 19:26:24 +01:00 Authoring application: mPDF 5.7
MD5: 3e9c6f433671122e6b2075e5a960bada SHA-1: 6666c8cedcb2be93da9f1cd6a5b7408032aa7b21 SHA-256: 04ae024804f348123dd1371eba14fe3208a0609c208768b4edad12012cb47ed2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, forming a link farm. The ML classifier also flagged this PDF as malicious. The primary purpose appears to be directing users to a large collection of other PDF files hosted on the same domain. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4095091094/Pretty-Lost-Dolls-Pretty-Little-Dolls-2-by-Ker-Dukey.pdf
    • http://loaminoo.linkpc.net/5094093094093098/Pretty-Broken-Dolls-Pretty-Little-Dolls-4-by-Ker-Dukey.pdf
    • http://loaminoo.linkpc.net/2099097094096092/Pretty-New-Doll-Pretty-Little-Dolls-3-by-Ker-Dukey.pdf
    • http://loaminoo.linkpc.net/6098095099099090/Pretty-Dolls-and-Hand-Grenades-by-Cara-Reinard.pdf
    • http://loaminoo.linkpc.net/1099095096098096/Midnight-Dolls-The-Dolls-2-by-Kiki-Sullivan.pdf
    • http://loaminoo.linkpc.net/2093090094093093/Pretty-is-as-Pretty-Dies-Myrtle-Clover-Mysteries-1-by-Elizabeth-Spann-Craig.pdf
    • http://loaminoo.linkpc.net/1090097098090096098/Pretty-Little-Ghost-Pretty-Little-Liars-Rosewood-Hotel-Mystery-2-by-M-B-Borchardt.pdf
    • http://loaminoo.linkpc.net/5094093094099098/All-Things-Pretty-Part-Two-Pretty-3-5-by-Michelle-Leighton.pdf
    • http://loaminoo.linkpc.net/4092090094094094/Pretty-Hot-Pretty-1-by-Donna-Alam.pdf
    • http://loaminoo.linkpc.net/4094097094099/Pretty-Guardian-Sailor-Moon-Vol-1-Pretty-Soldier-Sailor-Moon-Renewal-Edition-1-by-Naoko-Takeuchi.pdf
    • http://loaminoo.linkpc.net/2097099093095099/Pretty-Guardian-Sailor-Moon-Vol-3-Pretty-Soldier-Sailor-Moon-Renewal-Edition-3-by-Naoko-Takeuchi.pdf
    • http://loaminoo.linkpc.net/3090093092096096/Pretty-Crooked-Pretty-Crooked-1-by-Elisa-Ludwig.pdf
    • http://loaminoo.linkpc.net/1090097098096099/Dolls-by-Michael-Hiebert.pdf
    • http://loaminoo.linkpc.net/4099098095098097/Josephine-and-Her-Dolls-by-H-C-Cradock.pdf
    • http://loaminoo.linkpc.net/3096090091096097/Very-Dead-Dolls-by-Ian-Woodhead.pdf
    • http://loaminoo.linkpc.net/1099099093090090/Pretty-In-Black-Pretty-in-Black-1-by-Rae-Hachton.pdf
    • http://loaminoo.linkpc.net/5094093094091098/Pretty-in-Black-Pretty-in-Black-1-by-Rae-Hachton.pdf
    • http://loaminoo.linkpc.net/2098095095096093/Pretty-In-Black-Pretty-in-Black-1-by-Rae-Hachton.pdf
    • http://loaminoo.linkpc.net/3092094093093094/Valley-of-the-dolls-by-Jacqueline-Susann.pdf
    • http://loaminoo.linkpc.net/2093096099097092/The-Dolls-Christmas-by-Tasha-Tudor.pdf