Malicious PDF — malware analysis report

Static analysis result for SHA-256 04e047c9cc761bd5…

MALICIOUS

PDF

21.6 KB Created: 2019-04-30 05:29:05 +01:00 Authoring application: mPDF 5.7
MD5: 11113a7fbd5f578f36d07db364db9825 SHA-1: 8e716806a2d16dea2439bd26aaeb5c2d43742837 SHA-256: 04e047c9cc761bd5be3d4db06c485e3c92b00df0ff9779ee1a36db83c0dde84d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, forming a link farm. These URLs point to various PDF files, many of which appear to be related to tarot reading, suggesting a lure to external content. The ML classifier also flagged this PDF as malicious, supporting the suspicious nature of the link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091095094097097094/Tarot-for-Beginners-A-Guide-to-Psychic-Tarot-Reading-Real-Tarot-Card-Meanings-and-Simple-Tarot-Spreads-by-Lisa-Chamberlain.pdf
    • http://loaminoo.linkpc.net/8092097099092093/Amano-Tarot-Deck-Finding-Happiness-with-Tarot-Fortune-Telling-Shiwase-o-Tsukamu-Tarot-Uranai-Amano-Yoshitaka-Originaru-Kaado-78-Mai-in-Japanese-by-Emile-Scheherazade.pdf
    • http://loaminoo.linkpc.net/8098095095091093/A-Captive-of-Her-Love-Letters-and-Paintings-of-Janina-Stroka-by-Janina-Stroka.pdf
    • http://loaminoo.linkpc.net/1091095094097097095/Tarot-for-Beginners-An-Easy-Guide-to-Understanding-amp-Interpreting-the-Tarot-by-P-Scott-Hollander.pdf
    • http://loaminoo.linkpc.net/4090091095096092/The-Tarot-Revealed-A-Modern-Guide-to-Reading-the-Tarot-Cards-by-Eden-Gray.pdf
    • http://loaminoo.linkpc.net/1091095094098096098/Holistic-Tarot-An-Integrative-Approach-to-Using-Tarot-for-Personal-Growth-by-Benebell-Wen.pdf
    • http://loaminoo.linkpc.net/8092097098096095/Amano-Tarot-Deck-Finding-Happiness-With-Tarot-Fortune-Telling-by-Emile-Scheherazade.pdf
    • http://loaminoo.linkpc.net/1091095094095098093/Learning-the-Tarot-A-Tarot-Book-for-Beginners-by-Joan-Bunning.pdf
    • http://loaminoo.linkpc.net/4099097099098/Uncloaking-the-Tarot-A-Comprehensive-Course-in-Tarot-by-Brigid-Bishop.pdf
    • http://loaminoo.linkpc.net/5095092097098098/Understanding-Aleister-Crowley-s-Thoth-Tarot-An-Authoritative-Examination-of-the-World-s-Most-Fascinating-and-Magical-Tarot-Cards-by-Lon-Milo-DuQuette.pdf
    • http://loaminoo.linkpc.net/2093094097097093/God-of-Tarot-Tarot-1-by-Piers-Anthony.pdf
    • http://loaminoo.linkpc.net/1090090095094094094/Italian-Card-Games-Tarot-Tarocchini-Basset-Scopa-Tute-Cassino-Briscola-Buraco-Tarot-Tarock-and-Tarocchi-Games-Reversis-Minchia-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/7090096095098/If-All-The-Seas-Were-One-Sea-by-Janina-Domanska.pdf
    • http://loaminoo.linkpc.net/8098095094099099/Hotel-Janina-by-Eva-Arados.pdf
    • http://loaminoo.linkpc.net/8098095094096098/The-Understanding-of-Women-by-Janina-Matthewson.pdf
    • http://loaminoo.linkpc.net/1090098094099096090/Schenk-mir-dein-Vertrauen-by-Janina-Mantoni.pdf
    • http://loaminoo.linkpc.net/8098095093093090/Tovi-the-Penguin-Goes-Trick-or-Treating-by-Janina-Rossiter.pdf
    • http://loaminoo.linkpc.net/8098095093099098/The-Enchanted-Book-A-Tale-from-Krakow-by-Janina-Porazi-ska.pdf
    • http://loaminoo.linkpc.net/1090095090096099090/Der-Beginn-des-Krieges-EVENT-in-1939-1941-by-Janina-Muench.pdf
    • http://loaminoo.linkpc.net/8096092096098098/Star-Trek-Die-n-chste-Generation---Eine-H-lle-namens-Paradies-Star-Trek-The-Next-Generation-11-by-Peter-David.pdf