Malicious PDF — malware analysis report

Static analysis result for SHA-256 19ad1df56e44335e…

MALICIOUS

PDF

21.2 KB Created: 2019-04-30 04:58:32 +01:00 Authoring application: mPDF 5.7
MD5: 09d46247221fba79ead2588c7dce1fbb SHA-1: 8a5c3224e2cbecd52a944efa68e59d095d250d86 SHA-256: 19ad1df56e44335ecba319efe66d2e371aeef3e89c3b9fef1bd690023f6ca55d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier and contains a large number of embedded external links, indicating a link farm or redirection scheme. The primary heuristic identified a 'PDF_SEO_LINK_FARM' with 26 numeric slug links, suggesting an attempt to drive traffic to potentially malicious or unwanted content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1095091097091097/The-Christmas-Present-An-Erotic-Holiday-Story-by-Victoria-Primrose.pdf
    • http://loaminoo.linkpc.net/2099095096090098/Open-House-An-Erotic-Real-Estate-Story-by-Victoria-Primrose.pdf
    • http://loaminoo.linkpc.net/4096094090098097/All-He-Wants-For-Christmas-Eve-An-Erotic-Holiday-Story-by-Ruby-Carew.pdf
    • http://loaminoo.linkpc.net/2095093090093092/Punishing-Miss-Primrose-Parts-I---XX-The-Complete-Set-An-Erotic-Historical-in-the-Red-Chrysanthemum-Series-by-Em-Brown.pdf
    • http://loaminoo.linkpc.net/2098091092094097/Texas-K-9-Unit-Christmas-Holiday-Hero-Rescuing-Christmas-by-Shirlee-McCoy.pdf
    • http://loaminoo.linkpc.net/8098097098094/Risky-Christmas-Holiday-Secrets-Kidnapped-at-Christmas-by-Jill-Sorenson.pdf
    • http://loaminoo.linkpc.net/5090090091096097/I-ll-Be-Home-for-Christmas-Silver-Bells-On-a-Snowy-Christmas-The-Perfect-Holiday-by-Debbie-Macomber.pdf
    • http://loaminoo.linkpc.net/4098090097094092/This-Holiday-Magic-A-Gift-from-the-Heart-Mine-by-Christmas-A-Family-for-Christmas-by-Celeste-O-Norfleet.pdf
    • http://loaminoo.linkpc.net/1090091096097097098/Primrose-Past-The-1848-Journal-of-Young-Lady-Primrose-by-Caroline-Rose-Hunt.pdf
    • http://loaminoo.linkpc.net/1096090099095091/Jaya-s-Compromise-An-Indian-erotic-sex-story-desi-erotic-tales-Book-1-by-Reema.pdf
    • http://loaminoo.linkpc.net/1091094092090095097/A-Heartwarming-Christmas-A-Boxed-Set-of-Twelve-Sweet-Holiday-Romances-Christmas-Town-Maine-2-5-by-Melinda-Curtis.pdf
    • http://loaminoo.linkpc.net/3091096092097098/Puppy-in-a-Present-Animal-Ark-Holiday-Special-13-by-Ben-M-Baglio.pdf
    • http://loaminoo.linkpc.net/5090093091093092/Christmas-with-the-Poets-A-Collection-of-Songs-Carols-and-Descriptive-Verses-Relating-to-the-Festival-of-Christmas-from-the-Anglo-Norman-Period-to-the-Present-Time-by-Henry-Vizetelly.pdf
    • http://loaminoo.linkpc.net/8094094094094091/Cinder-An-Erotic-Modern-Fairy-Tale-by-Victoria-Brice.pdf
    • http://loaminoo.linkpc.net/3092099091095091/My-Lady-Gambler-Stories-of-erotic-romance-corsets-and-an-England-that-never-was-by-Victoria-Pond.pdf
    • http://loaminoo.linkpc.net/1093099097092099/Christmas-Holiday-by-W-Somerset-Maugham.pdf
    • http://loaminoo.linkpc.net/2094091091098098/Father-Christmas-Goes-on-Holiday-by-Raymond-Briggs.pdf
    • http://loaminoo.linkpc.net/4098090090096099/The-Christmas-Present-by-Larry-Benjamin.pdf
    • http://loaminoo.linkpc.net/2090096096095090/A-Present-for-Christmas-by-Shiloh-Walker.pdf
    • http://loaminoo.linkpc.net/4092095093090094/Trapped-with-Twins-for-Christmas-A-Holiday-MFM-Quickie-by-Kat-Crimson.pdf