Malicious PDF — malware analysis report

Static analysis result for SHA-256 087f2d917a8b3613…

MALICIOUS

PDF

18.6 KB Created: 2019-05-02 17:02:27 +01:00 Authoring application: mPDF 5.7
MD5: feb4b17c9ac92ed1c505b37468328251 SHA-1: 48da8dd2294f4d324cc3eb85e005a3f7d92b55c7 SHA-256: 087f2d917a8b3613d6f77aa6695eb871edb7786e5b0fd1c2d9b52273bae5a590
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, masquerading as book titles, which is indicative of a link farm or SEO spam tactic. While the URLs themselves are currently classified as benign, the sheer volume and the heuristic firing for PDF_SEO_LINK_FARM suggest a malicious intent to drive traffic or potentially distribute further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7093099098094/Haruko-Love-Poems-US-only-by-June-Jordan.pdf
    • http://loaminoo.linkpc.net/9091097091096/The-Voice-of-the-Children-by-June-Jordan.pdf
    • http://loaminoo.linkpc.net/1094091097090090/Some-of-Us-Did-Not-Die-New-and-Selected-Essays-by-June-Jordan.pdf
    • http://loaminoo.linkpc.net/4095098094092091/Living-Room-by-June-Jordan.pdf
    • http://loaminoo.linkpc.net/5091093098095092/Mushi-To-Uta-Ichikawa-Haruko-Sakuhinsh-1-by-Haruko-Ichikawa.pdf
    • http://loaminoo.linkpc.net/9091097099098/The-Cineaste-Poems-by-A-Van-Jordan.pdf
    • http://loaminoo.linkpc.net/1094096096097093/Love-s-Trusting-The-Love-s-3-by-Maryann-Jordan.pdf
    • http://loaminoo.linkpc.net/1094096099097099/Love-s-Tempting-The-Love-s-2-by-Maryann-Jordan.pdf
    • http://loaminoo.linkpc.net/5098097091090092/War-amp-Love-Love-amp-War-New-and-Selected-Poems-New-and-Selected-Poems-by-Aharon-Shabtai.pdf
    • http://loaminoo.linkpc.net/1091095096097095096/Diogee-A-Story-about-a-Grandmother-s-Love-for-Her-Grand-Dog-by-June-Allard-Berte.pdf
    • http://loaminoo.linkpc.net/1091095096097095095/Diogee-A-Story-about-a-Grandmother-s-Love-for-Her-Grand-Dog-by-June-Allard-Berte.pdf
    • http://loaminoo.linkpc.net/1091095096098092096/Diogee-A-Story-about-a-Grandmother-s-Love-for-Her-Grand-dog-by-June-Allard-Berte.pdf
    • http://loaminoo.linkpc.net/4090091098093/Finding-June-June-1-by-Shannen-Crane-Camp.pdf
    • http://loaminoo.linkpc.net/4090093098098097/Honey-I-Love-and-Other-Love-Poems-by-Eloise-Greenfield.pdf
    • http://loaminoo.linkpc.net/6099091092094093/Harlequin-Love-Inspired-June-2018---Box-Set-2-of-2-And-Cowboy-Makes-Three-His-Surprise-Son-The-Firefighter-s-Twins-by-Deb-Kastner.pdf
    • http://loaminoo.linkpc.net/3090091094096092/Permission-to-Love-by-Penny-Jordan.pdf
    • http://loaminoo.linkpc.net/3091099091093094/Love-Me-or-Miss-Me-Hot-Girl-Bad-Boy-by-Dream-Jordan.pdf
    • http://loaminoo.linkpc.net/2098094093090092/--Itoshi-no-Nekokke-by-Haruko-Kumota.pdf
    • http://loaminoo.linkpc.net/7098090099090/JOHN-DONNE-COMPLETE-WORKS-ULTIMATE-COLLECTION-All-Poems-Love-Poetry-Holy-Sonnets-Devotions-Meditations-English-Poems-Sermons-PLUS-BIOGRAPHIES-and-ANNOTATIONS-Annotated-by-John-Donne.pdf
    • http://loaminoo.linkpc.net/3094091092091096/Class-of-Love-Letters-From-Home-1-by-Maryann-Jordan.pdf