Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a682493b8a94709…

MALICIOUS

PDF

18.7 KB Created: 2019-04-30 03:29:00 +01:00 Authoring application: mPDF 5.7
MD5: 0d649924d267c34056e66a03cdc2d2c1 SHA-1: 79fe50e21038fa28b31f4a661ed3ea866dbc83f7 SHA-256: 2a682493b8a9470901404ada2628c38aab25a3e70a3580947d54635b8644722f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly indicated maliciousness. The embedded URLs, while appearing to link to books, are part of a link farm designed to direct users to potentially malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1093098091097099/West-from-Home-Letters-of-Laura-Ingalls-Wilder-San-Francisco-1915-Little-House-11-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/4096098092093/The-First-Four-Years-Little-House-9-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/2093093096094090/Laura-s-Early-Years-Collection-Little-House-1-2-4-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/1096099094095099/A-Little-House-Traveler-Writings-from-Laura-Ingalls-Wilder-s-Journeys-Across-America-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/3093094092091/These-Happy-Golden-Years-Little-House-8-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/1090094097091099/Little-House-in-the-Big-Woods-Farmer-Boy-Little-House-on-the-Prairie-On-the-Banks-of-Plum-Creek-By-the-Shores-of-Silver-Lake-Little-House-1-5-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/6095090098095/Little-House-on-the-Prairie-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/4097091094095098/Little-House-in-the-Big-Woods-Little-House-1-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/4096098091093/The-Little-House-Collection-Little-House-1-5-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/1091096099092092/Little-House-in-the-Big-Woods-Little-House-1-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/2097095092090091/The-Long-Winter-Little-House-6-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/3096094096095097/On-the-Banks-of-Plum-Creek-Little-House-4-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/3098099097090/By-the-Shores-of-Silver-Lake-Little-House-5-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/1095095094093099/On-the-Banks-of-Plum-Creek-Little-House-4-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/3092093095096093/By-the-Shores-of-Silver-Lake-Little-House-5-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/1095095094094091/By-the-Shores-of-Silver-Lake-Little-House-5-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/2095099097095098/By-the-Shores-of-Silver-Lake-Little-House-5-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/3098095095094095/The-Laura-Ingalls-Wilder-Country-Cookbook-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/6099095099092095/A-Little-House-Sampler-A-Collection-of-Early-Stories-and-Reminiscences-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/8092098092094095/My-Little-House-Crafts-Book-18-Projects-from-Laura-Ingalls-Wilder-s-by-Carolyn-Strom-Collins.pdf