Malicious PDF — malware analysis report

Static analysis result for SHA-256 340d4fbf656dd322…

MALICIOUS

PDF

21.5 KB Created: 2019-05-02 06:50:52 +01:00 Authoring application: mPDF 5.7
MD5: 6754645c603381361c76b2ef7cf48b98 SHA-1: 087e5c7db24c98a363105364ce805c629477196f SHA-256: 340d4fbf656dd322706637d1f790d52f09df6c188b660bb4d6170ad2bccde0ab
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous external links suggests a malicious intent, possibly for SEO manipulation or to distribute further payloads. The ML_NYX_PDF_MALICIOUS heuristic also flags the document as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8095090090095091/Cupcake-Soap-Sweets-deco-made-by-soap-by-Yuki-Deschene.pdf
    • http://loaminoo.linkpc.net/1099099098093095/Soap-Soap-Don-t-Forget-the-Soap-An-Appalachain-Folktale-by-Tom-Birdseye.pdf
    • http://loaminoo.linkpc.net/6090092097097092/Soap-Making-Homemade-Organic-Soap-Making-Made-Simple-and-Safe-for-Beginners-by-Elizabeth-Aron.pdf
    • http://loaminoo.linkpc.net/8094099099099092/Glass-Flowers-Computer-graphics-made-with-shade-by-Yuki-Deschene.pdf
    • http://loaminoo.linkpc.net/8095090090095090/cakesoap-by-Yuki-Deschene.pdf
    • http://loaminoo.linkpc.net/1091094099098096098/Soap-by-Francis-Ponge.pdf
    • http://loaminoo.linkpc.net/2093090093098096/Soap-Opera-by-Alecia-Swasy.pdf
    • http://loaminoo.linkpc.net/9092098095095/The-Biggest-Soap-by-Carole-Lexa-Schaefer.pdf
    • http://loaminoo.linkpc.net/2097096094097097/The-Phantom-of-the-Soap-Opera-by-Judi-Miller.pdf
    • http://loaminoo.linkpc.net/2093094090093091/Love-Ain-t-No-Soap-Opera-Shadybrook-1-by-Connie-Kuykendall.pdf
    • http://loaminoo.linkpc.net/3092091090090097/Killing-Kelly-Soap-Opera-3-by-Heather-Graham.pdf
    • http://loaminoo.linkpc.net/9096092092091096/10-Homemade-Laundry-Soap-Detergent-Recipes-by-Natan-Snider.pdf
    • http://loaminoo.linkpc.net/3096095092092091/My-Own-Personal-Soap-Opera-Looking-for-Reality-in-All-the-Wrong-Places-by-Libby-Malin.pdf
    • http://loaminoo.linkpc.net/8099091099099095/Making-Transparent-Soap-The-Art-Of-Crafting-Molding-Scenting-Coloring-by-Catherine-Failor.pdf
    • http://loaminoo.linkpc.net/4096095097097092/The-Cupcake-Cowboy-Lone-Star-Sweets-1-by-Lissa-Matthews.pdf
    • http://loaminoo.linkpc.net/1090096094096093097/Beeswax-Alchemy-How-to-Make-Your-Own-Soap-Candles-Balms-Creams-and-Salves-from-the-Hive-by-Petra-Ahnert.pdf
    • http://loaminoo.linkpc.net/4099097090093095/The-Fan-Who-Knew-Too-Much-Aretha-Franklin-the-Rise-of-the-Soap-Opera-Children-of-the-Gospel-Church-and-Other-Meditations-by-Anthony-Heilbut.pdf
    • http://loaminoo.linkpc.net/1090094095097093099/The-Art-of-Perfumery-and-Methods-of-Obtaining-the-Aromas-of-Plants-How-to-make-perfumes-scented-powders-aromatic-vinegars-dentifrices-pomatums-cosmetics-perfumed-soap-and-more-by-G-W-Septimus-Piesse.pdf
    • http://loaminoo.linkpc.net/3090090095098092/Earth-Moon-Colony-One---Soap-Opera-Sci-Fi---Love-Murder-and-Lust-Because-Men-and-Women-Will-Continue-to-Lust---Episode-Collection-I-by-K-Leslie-Graves.pdf
    • http://loaminoo.linkpc.net/4097091096098/Katie-and-the-Cupcake-Cure-Cupcake-Diaries-1-by-Coco-Simon.pdf