Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d3df7fee6176bea…

MALICIOUS

PDF

14.7 KB Created: 2019-04-30 03:52:02 +01:00 Authoring application: mPDF 5.7
MD5: ab127db5f9d5ad4f52963fd51d1d5b57 SHA-1: 9c625bfd88b02c606dd183a42e8ddec985894987 SHA-256: 1d3df7fee6176beaffc65664761e4d350b800d4a5907e078a7ecdb77bf5b3618
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified as a PDF_SEO_LINK_FARM heuristic. The primary purpose appears to be to create a link farm, potentially for SEO manipulation or to distribute further malicious content. While the specific URLs are marked as benign, the sheer volume and structure suggest a malicious intent to leverage the PDF for external linking. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6098096092090091/Fated-Vanguard-Legacy-3-by-Joanne-Kershaw.pdf
    • http://loaminoo.linkpc.net/6098096092090093/Vanguard-Legacy-2-Reflected-by-Joanne-Kershaw.pdf
    • http://loaminoo.linkpc.net/1091091093096091098/An-Ill-Fated-Sky-A-Star-Reckoner-s-Legacy-2-by-Darrell-Drake.pdf
    • http://loaminoo.linkpc.net/6098096092092099/Kershaw-s-Brigade-at-Gettysburg-by-Joseph-Brevard-Kershaw.pdf
    • http://loaminoo.linkpc.net/6098096092090090/Clayton-Kershaw-The-Inspirational-Story-of-Baseball-Superstar-Clayton-Kershaw-by-Bill-Redban.pdf
    • http://loaminoo.linkpc.net/3097099091090093/Fated-Saga-Book-Bundle-Awaken-Shifting-Fated-Saga-1-2-by-Rachel-M-Humphrey-D-39-aigle.pdf
    • http://loaminoo.linkpc.net/1090096099095090/Fated-Fated-1-by-Sarah-Alderson.pdf
    • http://loaminoo.linkpc.net/1090092098096099095/Vanguard-The-Genesis-Fleet-1-by-Jack-Campbell.pdf
    • http://loaminoo.linkpc.net/2095097092091095/Goldrush-Vanguard-Prime-1-by-Steven-Lochran.pdf
    • http://loaminoo.linkpc.net/3093091095092090/The-Secret-Vanguard-Sir-John-Appleby-5-by-Michael-Innes.pdf
    • http://loaminoo.linkpc.net/4090094099090096/Bootcamp-of-Misfit-Wolves-Vanguard-Elite-1-by-Annie-Nicholas.pdf
    • http://loaminoo.linkpc.net/4097094099093098/The-Legacy-Forgotten-Realms-Legacy-of-the-Drow-1-Legend-of-Drizzt-7-by-R-A-Salvatore.pdf
    • http://loaminoo.linkpc.net/8092093096097/The-Legacy-Forgotten-Realms-Legacy-of-the-Drow-1-Legend-of-Drizzt-7-by-R-A-Salvatore.pdf
    • http://loaminoo.linkpc.net/2092098092097096/Legacy-Lost-The-Syrena-Legacy-0-5-by-Anna-Banks.pdf
    • http://loaminoo.linkpc.net/4099091091094093/Amelia-s-Legacy-Legacy-1-by-Betty-Thomason-Owens.pdf
    • http://loaminoo.linkpc.net/1094095091094093/For-Love-or-Legacy-Legacy-Collection-2-by-Ruth-Cardello.pdf
    • http://loaminoo.linkpc.net/6094097099097095/Legacy-The-Legacy-Trilogy-Book-1-by-Corina-Zurcher.pdf
    • http://loaminoo.linkpc.net/1090096096093095093/Legacy-Legacy-of-the-Mist-Clans-Box-Set-by-Kathryn-Loch.pdf
    • http://loaminoo.linkpc.net/4095097098097/Hitler-by-Ian-Kershaw.pdf
    • http://loaminoo.linkpc.net/2090092091095096/The-Nightingale-Legacy-Legacy-2-by-Catherine-Coulter.pdf
    • http://loaminoo.linkpc.net/4090094099090096/Bootc