Malicious PDF — malware analysis report

Static analysis result for SHA-256 33d93c1ed8d52933…

MALICIOUS

PDF

15.6 KB Created: 2019-04-30 08:59:26 +01:00 Authoring application: mPDF 5.7
MD5: 1d3986ec1294a3b1d2f8c1a378689dfb SHA-1: 0c0aaf3d4a58a7e597acb47fb18d5a9549037f03 SHA-256: 33d93c1ed8d529333e7677f9000b3606f3c070b6665b52cf03ef4753c4159b29
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. The embedded URLs appear to be part of a link farm designed to attract traffic, likely for SEO purposes or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/2091099090099095/Maggie-Goes-to-Hollywood-Maggie-MacKay-Magical-Tracker-6-by-Kate-Danley.pdf
    • http://loaminoo.linkpc.net/2091099090098090/Maggie-Get-Your-Gun-Maggie-MacKay-Magical-Tracker-2-by-Kate-Danley.pdf
    • http://loaminoo.linkpc.net/2091099090098095/The-Ghost-and-Ms-MacKay-Maggie-MacKay-Magical-Tracker-2-5-by-Kate-Danley.pdf
    • http://loaminoo.linkpc.net/2091099090099093/The-M-Team-Maggie-MacKay-Magical-Tracker-5-by-Kate-Danley.pdf
    • http://loaminoo.linkpc.net/2091099090099090/M-amp-K-Tracking-Maggie-MacKay-Magical-Tracker-4-by-Kate-Danley.pdf
    • http://loaminoo.linkpc.net/2090096095094092/You-re-Mine-Maggie-The-Misadventures-of-Maggie-Mae-2-by-Beth-Yarnall.pdf
    • http://loaminoo.linkpc.net/2090096098096095/Find-Me-Maggie-The-Misadventures-of-Maggie-Mae-3-by-Beth-Yarnall.pdf
    • http://loaminoo.linkpc.net/2099095093099098/Tip-It-The-World-According-to-Maggie-by-Maggie-Griffin.pdf
    • http://loaminoo.linkpc.net/8094094090096092/Audition-for-Murder-Maggie-Ryan-1967-Maggie-Ryan-and-Nick-O-Connor-1-by-P-M-Carlson.pdf
    • http://loaminoo.linkpc.net/2097092097097/Murder-Is-Academic-Maggie-Ryan-1968-Maggie-Ryan-and-Nick-O-Connor-2-by-P-M-Carlson.pdf
    • http://loaminoo.linkpc.net/7092091098092094/Terminal-Ambition-A-Maggie-Mahoney-Novel-by-Kate-McGuinness.pdf
    • http://loaminoo.linkpc.net/4097092093095093/Queen-Mab-by-Kate-Danley.pdf
    • http://loaminoo.linkpc.net/7093099092099094/Queen-Joanna-by-Kate-Danley.pdf
    • http://loaminoo.linkpc.net/7099098091096/Mad-About-The-Boy-by-Maggie-Alderson.pdf
    • http://loaminoo.linkpc.net/3093097096098091/After-You-d-Gone-by-Maggie-O-39-Farrell.pdf
    • http://loaminoo.linkpc.net/4098092095099093/So-Right-With-You-by-Maggie-Kaye.pdf
    • http://loaminoo.linkpc.net/1092096096093090/The-Ice-People-by-Maggie-Gee.pdf
    • http://loaminoo.linkpc.net/3094095090090094/My-Cleaner-by-Maggie-Gee.pdf
    • http://loaminoo.linkpc.net/1094096095095095/Heart-of-Thorne-by-Maggie-Way.pdf
    • http://loaminoo.linkpc.net/5091093095095091/Looking-for-Evelyn-by-Maggie-Ritchie.pdf