Malicious PDF — malware analysis report

Static analysis result for SHA-256 30a01728caa2380b…

MALICIOUS

PDF

14.7 KB Created: 2019-05-01 05:13:03 +01:00 Authoring application: mPDF 5.7
MD5: 3022dea851c088b67d32c0d954843a44 SHA-1: caf1de809be75455195f4d62ce827cfa49426d1b SHA-256: 30a01728caa2380b0eea2a451ecd0b1b5b8825933a6de17486fedd51b8518241
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. These URLs point to what appear to be book titles, suggesting a lure to disguise malicious intent. The primary attack pattern involves leveraging these links, potentially for SEO manipulation or to direct users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096090091097099/Codename-Zero-The-Codename-Conspiracy-1-by-Chris-Rylander.pdf
    • http://loaminoo.linkpc.net/9096093097092098/Codename-Summer-Codename-Rebellion-4-by-Cyndi-Friberg.pdf
    • http://loaminoo.linkpc.net/9096093097091096/Codename-Chandler-Trilogy---Three-Complete-Novels-Codename-Chandler-1-3-by-J-A-Konrath.pdf
    • http://loaminoo.linkpc.net/3099099091099095/Codename-Wolf-by-Gil-Hogg.pdf
    • http://loaminoo.linkpc.net/4092090090097/Codename-Chimera-by-J-K-Persy.pdf
    • http://loaminoo.linkpc.net/3094093094091095/Codename-Villanelle-by-Luke-Jennings.pdf
    • http://loaminoo.linkpc.net/5099091098098097/My-Story-Codename-C-line-by-Jim-Eldridge.pdf
    • http://loaminoo.linkpc.net/9096093098097093/Codename-Gauntlet-by-Cassandra-Cole.pdf
    • http://loaminoo.linkpc.net/9096093098096090/Codename-Apache-by-Aubrey-James.pdf
    • http://loaminoo.linkpc.net/9096093099095097/Codename-Apache-by-Cassandra-Cole.pdf
    • http://loaminoo.linkpc.net/9096093098095099/Codename-Velocity-by-Schuyler-Thorpe.pdf
    • http://loaminoo.linkpc.net/9096093097099095/Codename-Nokken-by-Uberto-Ceretoli.pdf
    • http://loaminoo.linkpc.net/2091093091093093/X-Men-Codename-Wolverine-by-Christopher-Golden.pdf
    • http://loaminoo.linkpc.net/1092093098094097/Exposed-Codename-Chandler-0-2-by-J-A-Konrath.pdf
    • http://loaminoo.linkpc.net/9096093097098092/Codename-Lazarus-The-Spy-Who-Came-Back-From-The-Dead-by-A-P-Martin.pdf
    • http://loaminoo.linkpc.net/2094098096092094/Codename-UnSub-The-Last-Survivors-2-by-Declan-Finn.pdf
    • http://loaminoo.linkpc.net/9092095090094095/Kleiner-K-rbis---gro-er-Traum-by-Codename-Kolibri.pdf
    • http://loaminoo.linkpc.net/3097094094092098/Codename-Knockout-Volume-1-The-Devil-You-Say-by-Robert-Rodi.pdf
    • http://loaminoo.linkpc.net/9096093098096097/Audio-Assault-Codename-Winger-3-by-Jeff-Adams.pdf
    • http://loaminoo.linkpc.net/9096093099096091/Codename-Omega-Traitor-in-the-Tower-by-Jessica-Meats.pdf
    • http://loaminoo.linkpc.net/2091093091093093/X-Men-Codename-Wolverin