Malicious PDF — malware analysis report

Static analysis result for SHA-256 0daf4296c4ae4cf6…

MALICIOUS

PDF

16.8 KB Created: 2019-04-30 06:45:56 +01:00 Authoring application: mPDF 5.7
MD5: 239bd0a51b82ea7b3a27cb032f4eb549 SHA-1: 9e25144afa8052db99ffe4ee35960c8acb44fb63 SHA-256: 0daf4296c4ae4cf6a95e1eb9919aed7e37ec1713f9f5326e42b20a76b868a7a5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to host malicious content. The ML classifier strongly indicated maliciousness, and the PDF structure suggests an attempt to redirect users to a link farm. While the URLs themselves are marked as benign, the sheer volume and the heuristic firing indicate a suspicious pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9094092092092/Acheron-Dark-Hunter-8-Entire-Dark-Hunterverse-15-Dark-Hunterverse-23-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/3090091091091095/Dark-Bites-Dream-Hunter-1-Hellchaser-1-Were-Hunter-1-Dark-Hunter-2-5-2-6-7-5-9-5-9-6-10-5-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/4097094099097099/Dark-Side-of-the-Moon-Dark-Hunter-9-Were-Hunter-3-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/6092098090/Dragonsworn-Dark-Hunter-26-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/4097095090099/Styxx-Dark-Hunter-23-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1092092090091091/Styxx-Dark-Hunter-23-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/3098099094093/The-Guardian-Dark-Hunter-20-Dream-Hunter-5-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1099091098095096/Night-Embrace-Dark-Hunter-2-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/2090098095099/Dance-with-the-Devil-Dark-Hunter-3-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/8096098096097099/Gebieterin-der-Schatten-Dark-Hunter-15-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/3095092091093/Kiss-of-the-Night-Dark-Hunter-4-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/2098099090090092/Kiss-of-the-Night-Dark-Hunter-5-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1099092091099099/Kiss-of-the-Night-Dark-Hunter-4-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1094098091098098/Dragonbane-Dark-Hunter-Novels-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1091096094095093/Seize-the-Night-Dark-Hunter-5-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1099098099097096/Fantasy-Lover-Dark-Hunter-1-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/4098090095090093/Night-Embrace-Dark-Hunter-2-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/4096098092094/Upon-the-Midnight-Clear-Dark-Hunter-12-Dream-Hunter-2-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1096094099091096/Bad-Moon-Rising-Dark-Hunter-18-Were-Hunter-4-Hellchaser-2-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/2098090098094096/Unleash-the-Night-Dark-Hunter-9-Were-Hunter-4-by-Sherrilyn-Kenyon.pdf