Malicious PDF — malware analysis report

Static analysis result for SHA-256 0cc0a169f3514a70…

MALICIOUS

PDF

15.8 KB Created: 2019-05-02 05:37:34 +01:00 Authoring application: mPDF 5.7
MD5: ceaaa41cb1e8ae3a688f1262337e017a SHA-1: 42c9475aa91da0fa7fbd67d90a2a569bb69f31b7 SHA-256: 0cc0a169f3514a70c8ced2df277d67d1034aee6d605ae36c07dcd269a221971b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, forming a link farm. The heuristic PDF_SEO_LINK_FARM indicates this is a technique to generate traffic or distribute content. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent to redirect users. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095096097099/Temptation-amp-Twilight-The-Brethren-Guardians-3-by-Charlotte-Featherstone.pdf
    • http://loaminoo.linkpc.net/3099092094097094/Temptation-amp-Twilight-The-Brethren-Guardians-3-by-Charlotte-Featherstone.pdf
    • http://loaminoo.linkpc.net/1092093094090091/Sinful-Addicted-2-by-Charlotte-Featherstone.pdf
    • http://loaminoo.linkpc.net/6098095091099095/Quelques-mots-br-lants-by-Charlotte-Featherstone.pdf
    • http://loaminoo.linkpc.net/4092092097095096/Sinful-Epilogue-Addicted-2-1-by-Charlotte-Featherstone.pdf
    • http://loaminoo.linkpc.net/1092092091093096/Lust-The-Sins-and-The-Virtues-1-by-Charlotte-Featherstone.pdf
    • http://loaminoo.linkpc.net/1094095091097091/Entice-Me-at-Twilight-Doomsday-Brethren-4-by-Shayla-Black.pdf
    • http://loaminoo.linkpc.net/4099092090094/Addicted-Addicted-1-by-Charlotte-Featherstone.pdf
    • http://loaminoo.linkpc.net/4095090092097090/Enter-the-Brethren-Brethren-of-the-Coast-1-by-Barbara-Devlin.pdf
    • http://loaminoo.linkpc.net/4096097097090/Brethren-Brethren-Trilogy-1-by-Robyn-Young.pdf
    • http://loaminoo.linkpc.net/4090096091099097/At-Twilight-Born-in-Twilight-Beyond-Twilight-Wings-in-the-Night-4-amp-5-by-Maggie-Shayne.pdf
    • http://loaminoo.linkpc.net/2091091095093092/Temptation-Unleashed-Temptation-Trilogy-1-by-Sherry-Stanfield.pdf
    • http://loaminoo.linkpc.net/3092091096092094/Temptation-s-Edge-Sons-of-Temptation-2-by-Tanya-Holmes.pdf
    • http://loaminoo.linkpc.net/2099095096094098/Wrestling-With-Temptation-Temptation-Wyoming-1-by-Zoey-Marcel.pdf
    • http://loaminoo.linkpc.net/2095095094098/Twilight-Fulfilled-Wings-in-the-Night-18-Children-of-Twilight-2-by-Maggie-Shayne.pdf
    • http://loaminoo.linkpc.net/3095092097090/The-Twilight-Saga-The-Official-Illustrated-Guide-Twilight-4-5-by-Stephenie-Meyer.pdf
    • http://loaminoo.linkpc.net/1091099093091095094/Twilight-Midnight-Sun-Edward-s-Version-of-The-Twilight-Saga-A-Parody-by-E-Cullen.pdf
    • http://loaminoo.linkpc.net/2098091095094090/Twilight-Life-and-Death-Twilight-1-1-75-by-Stephenie-Meyer.pdf
    • http://loaminoo.linkpc.net/5095092099096/Twilight-Life-and-Death-Twilight-1-1-75-by-Stephenie-Meyer.pdf
    • http://loaminoo.linkpc.net/1097094099096091/Within-Temptation-Sons-of-Temptation-1-by-Tanya-Holmes.pdf