Malicious PDF — malware analysis report

Static analysis result for SHA-256 19a0534f65d20a51…

MALICIOUS

PDF

21.0 KB Created: 2019-05-07 02:55:08 +01:00 Authoring application: mPDF 5.7
MD5: f91f2cad1a29df30bbe6199fb7df0e9b SHA-1: de64a540dcb1f556c7d94b7ab4e0b1de879d502c SHA-256: 19a0534f65d20a5122d54de65588fade224dc151488ecfd659f9d01ac6a648ba
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, disguised as book titles, which are all hosted on the same domain. This pattern is indicative of a link farm designed to drive traffic or potentially host malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6090097094094097/Curmudgeon-s-Waif-A-Love-Story-Not-a-Romance-by-Valerie-J-Deguise.pdf
    • http://loaminoo.linkpc.net/8094093098097/The-Epic-Love-Story-of-Doug-and-Stephen-by-Valerie-Z-Lewis.pdf
    • http://loaminoo.linkpc.net/1090093095090096097/Love-is-the-Only-Story-Tales-of-Romance-by-Ben-Schrank.pdf
    • http://loaminoo.linkpc.net/6096093094090099/Family-Romance-A-Love-Story-by-John-Lanchester.pdf
    • http://loaminoo.linkpc.net/4096092092095097/The-Lady-of-the-Lakes-The-True-Love-Story-of-Sir-Walter-Scott-Historical-Proper-Romance-2-by-Josi-S-Kilpack.pdf
    • http://loaminoo.linkpc.net/9098098099098095/BBW-BWWM-Shifter-Romance-Lion-Prince-s-Love-In-The-Snow-Paranormal-Suspense-Alpha-Male-Fantasy-Shifter-Romance-Werewolf-Vampire-Shapeshifter-New-Adult-Romance-by-Jenny-Wildner.pdf
    • http://loaminoo.linkpc.net/4098092092098092/Thrown-For-A-Loop-A-romance-story-of-A-hockey-player-and-a-figure-skating-find-common-ground-and-love-by-Stephanie-Hatem.pdf
    • http://loaminoo.linkpc.net/4099094091095092/Secretly-Yours-Riverbend-Romance-1-by-Valerie-Comer.pdf
    • http://loaminoo.linkpc.net/1097094098096099/Standard-Romance-Story-Fireman-Edition-Standard-Romance-Story-1-by-M-S-Willis.pdf
    • http://loaminoo.linkpc.net/1098098092095099/Raspberries-and-Vinegar-A-Farm-Fresh-Romance-1-by-Valerie-Comer.pdf
    • http://loaminoo.linkpc.net/3095098097091095/Dandelions-for-Dinner-A-Farm-Fresh-Romance-4-by-Valerie-Comer.pdf
    • http://loaminoo.linkpc.net/6092092095098095/LESBIAN-ROMANCE-Lesbian-Romance-Story-The-Coming-Out-An-Unexpected-Adventure----lesbian-romance-lesbian-fiction---by-Juliet-Plaisir.pdf
    • http://loaminoo.linkpc.net/3095091096092090/Special-Delivery-Valentine-An-Office-Romance-Short-Story-Lesbian-Office-Romance-Series-Book-2-by-Roz-Lee.pdf
    • http://loaminoo.linkpc.net/9095090092092099/Amish-Romance-The-Promise-Hollybrook-Amish-Romance-Greta-s-Story-Book-2-by-Brenda-Maxfield.pdf
    • http://loaminoo.linkpc.net/9098090091093098/The-Curmudgeon-s-Guide-to-Practicing-Law-by-Mark-Herrmann.pdf
    • http://loaminoo.linkpc.net/2095096090099092/Perilous-Waif-Alice-Long-1-by-E-William-Brown.pdf
    • http://loaminoo.linkpc.net/3092095097099099/Changes-for-Kit-A-Winter-Story-by-Valerie-Tripp.pdf
    • http://loaminoo.linkpc.net/6098099097095096/The-Story-of-Mustgofast-by-Valerie-A-Beauchene.pdf
    • http://loaminoo.linkpc.net/1095093092094099/Changes-for-Josefina-A-Winter-Story-by-Valerie-Tripp.pdf
    • http://loaminoo.linkpc.net/2090098096093098/Felicity-s-Story-Collection-with-Other-by-Valerie-Tripp.pdf