Malicious PDF — malware analysis report

Static analysis result for SHA-256 11addde4b1ac92c1…

MALICIOUS

PDF

12.8 KB Created: 2019-04-30 01:43:22 +01:00 Authoring application: mPDF 5.7
MD5: 6760e6348be699625e624596858a94dc SHA-1: 1fb585710b6b5cf10de2584b531e689bc700613c SHA-256: 11addde4b1ac92c1e940ad24f869252308eefa75fa243e331b296b4e8be4a1ee
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which suggests a link farm or redirection to malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. While no scripts were extracted, the embedded links are the primary indicators of malicious activity, likely leading to a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9006

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1092093095091096/Branded-by-Gold-Men-in-Love-1-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/1096090098091095/Going-Against-Orders-Men-in-Love-5-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/2093090098097098/Recipe-for-Love-Cattle-Valley-15-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/4094098093098091/Sex-With-Lex-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/1091099090095094090/It-Was-a-Thursday-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/4099095094094099/Between-Two-Lovers-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/2091097091095094/No-Longer-His-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/4094098091099091/Stepping-Stones-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/3093093092097090/Saving-Noah-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/1096090096095097/Hunting-Evil-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/3093090094093099/Harvest-Heat-Australian-1-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/2095095093092090/Out-of-the-Shadow-Cattle-Valley-6-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/1090091090096094093/The-Claiming-of-Patrick-Donnelly-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/3093092097097091/Second-Chances-Cattle-Valley-28-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/3093092097095095/Confessions-Cattle-Valley-25-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/3093092090091099/The-O-Brien-Way-Cattle-Valley-21-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/3093090094094091/Gone-Surfin-Cattle-Valley-9-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/1096091092095094/Crimson-Moon-Neo-s-Realm-3-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/3093090094094090/The-Injustice-of-Being-Campus-Cravings-16-by-Carol-Lynne.pdf
    • http://loaminoo.linkpc.net/2093090097092096/Bareback-Cowboy-Saddle-Up-and-Ride-2-by-Carol-Lynne.pdf