Malicious PDF — malware analysis report

Static analysis result for SHA-256 19391ddae92b6acf…

MALICIOUS

PDF

17.1 KB Created: 2019-05-05 16:01:30 +01:00 Authoring application: mPDF 5.7
MD5: 027e2c886f0cd06df377eeceead9f844 SHA-1: be2eddfd0c65ae517e5f485887013c2ab5c57c69 SHA-256: 19391ddae92b6acf00a806974f9818f8855f6b438d42b0d9c3d7c1515eba8869
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and structure suggest an attempt to manipulate search engine results or to distribute content, potentially malicious, through a link farm. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090090093098096/Blood-Prize-the-Running-Veins-Series-1-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/4091092091096095/A-Murder-Inc-Volume-1-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/2090090093093096/Black-Snow-Vampire-Empire-3-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/7098092091091/The-Book-of-Blood-From-Legends-and-Leeches-to-Vampires-and-Veins-by-H-P-Newquist.pdf
    • http://loaminoo.linkpc.net/2093092091090091/Blood-in-Her-Veins-Nineteen-Stories-from-the-World-of-Jane-Yellowrock-by-Faith-Hunter.pdf
    • http://loaminoo.linkpc.net/4091092091094099/Creatures-of-the-Night-Creatures-1-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/4091092093090094/Creatures-of-the-Light-Creatures-5-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/2093093095092093/Area-1-Area-1-2-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/3096096091095092/Area-1-Area-1-1-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/9095098094091099/Talking-to-Strangers-Brittingham-Prize-in-Poetry-Series-by-Patricia-Dobler.pdf
    • http://loaminoo.linkpc.net/5094092097093096/Stella-and-Sol-The-Complete-Series-by-Kimberly-Loth.pdf
    • http://loaminoo.linkpc.net/1091090097099098092/Running-Run-Yourself-Slim-The-Daily-Running-Habit-for-Healthy-Weight-Loss-Without-Dieting-and-Drugs-Running-Slimming-Run-Losing-Weight-by-Emily-Darin.pdf
    • http://loaminoo.linkpc.net/2090090093098093/Vampire-Empire-Vampire-Empire-0-5-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/1091096098090093093/Blood-Lust-Blood-Series-3-by-T-Lynne-Tolles.pdf
    • http://loaminoo.linkpc.net/1092091090099099/Running-with-the-Devil-Plantain-MC-Series-1-by-Amelia-Oliver.pdf
    • http://loaminoo.linkpc.net/3091096093090/Writers-of-the-Purple-Sage-Purple-Sage-Mystery-1-by-Barbara-Burnett-Smith.pdf
    • http://loaminoo.linkpc.net/4096098097090093/Rambo-First-Blood-Part-II-Rambo-First-Blood-Series-Book-2-by-David-Morrell.pdf
    • http://loaminoo.linkpc.net/7093097099094091/Running-Is-Flying-Aphorisms-Meditations-and-Thoughts-on-a-Running-Life-by-Paul-E-Richardson.pdf
    • http://loaminoo.linkpc.net/1090092096090095096/My-Running-Years-A-Personal-Story-of-Running-Experiences-by-Alan-Seel.pdf
    • http://loaminoo.linkpc.net/1090092096090094099/Running-Jargon-Explained-An-Expanded-A-to-Z-of-Running-Terms-by-Alan-Seel.pdf