Malicious PDF — malware analysis report

Static analysis result for SHA-256 13cc18aee3b8c8d8…

MALICIOUS

PDF

18.6 KB Created: 2019-05-02 01:27:52 +01:00 Authoring application: mPDF 5.7
MD5: 13da01a85d1e09de8ad980f8136d94e1 SHA-1: c8e4da2ef51924964c1817b1d950a5e32229643f SHA-256: 13cc18aee3b8c8d899803d49f29abebd17967423e8fc7523d121cdf165a23d0e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm that directs users to external PDF documents. This behavior is indicative of a SEO poisoning or link-farming attack, likely intended to drive traffic or potentially distribute further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3094090091094097/Elizabeth-of-York-The-Forgotten-Tudor-Queen-by-Amy-Licence.pdf
    • http://loaminoo.linkpc.net/3093099092092094/Plantagenet-Princess-Tudor-Queen-The-Story-of-Elizabeth-of-York-by-Samantha-Wilcoxson.pdf
    • http://loaminoo.linkpc.net/2095096092093098/The-Temptation-of-Elizabeth-Tudor-Elizabeth-I-Thomas-Seymour-and-the-Making-of-a-Virgin-Queen-by-Elizabeth-Norton.pdf
    • http://loaminoo.linkpc.net/8095099094096097/The-Queen-s-Fool-The-Tudor-Court-4-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/3094090091095093/Mary-Tudor-The-White-Queen-by-Walter-C-Richardson.pdf
    • http://loaminoo.linkpc.net/1096098098095098/A-Favorite-of-the-Queen-Tudor-Saga-11-by-Jean-Plaidy.pdf
    • http://loaminoo.linkpc.net/1097092090095096/The-King-s-Daughter-A-Novel-of-the-First-Tudor-Queen-by-Sandra-Worth.pdf
    • http://loaminoo.linkpc.net/1095092094094097/Mary-Tudor-Princess-Bastard-Queen-by-Anna-Whitelock.pdf
    • http://loaminoo.linkpc.net/1097098097097093/Counting-One-s-Blessings-The-Selected-Letters-of-Queen-Elizabeth-the-Queen-Mother-by-William-Shawcross.pdf
    • http://loaminoo.linkpc.net/3091098093097097/Katherine-of-Aragon-The-True-Queen-Six-Tudor-Queens-1-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/2096091092096093/Katherine-of-Aragon-the-True-Queen-Six-Tudor-Queens-1-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3092096090/Katherine-of-Arag-n-The-True-Queen-Six-Tudor-Queens-1-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/4090093095095093/Five-Gold-Rings-A-Royal-Wedding-Souvenir-Album-from-Queen-Victoria-to-Queen-Elizabeth-II-by-Jane-Roberts.pdf
    • http://loaminoo.linkpc.net/3093098099096093/Watch-the-Lady-The-Tudor-Trilogy-3-by-Elizabeth-Fremantle.pdf
    • http://loaminoo.linkpc.net/4092097091091096/Queen-Elizabeth-s-Daughter-A-Novel-of-Elizabeth-I-by-Anne-Clinard-Barnhill.pdf
    • http://loaminoo.linkpc.net/2097094092090092/The-Sisters-Who-Would-Be-Queen-Mary-Katherine-and-Lady-Jane-Grey-A-Tudor-Tragedy-by-Leanda-de-Lisle.pdf
    • http://loaminoo.linkpc.net/4094092094090093/Rose-Bride-Lust-in-the-Tudor-Court-3-by-Elizabeth-Moss.pdf
    • http://loaminoo.linkpc.net/1095091092095092/Wolf-Bride-Lust-in-the-Tudor-Court-1-by-Elizabeth-Moss.pdf
    • http://loaminoo.linkpc.net/3093099095098091/Elizabeth-the-Queen-The-Lady-Elizabeth-by-Alison-Weir.pdf
    • http://loaminoo.linkpc.net/3094091095099094/The-Forgotten-Aten-s-Last-Queen-by-J-Lynn-Else.pdf