Malicious PDF — malware analysis report

Static analysis result for SHA-256 37d171d0f8414124…

MALICIOUS

PDF

13.1 KB Created: 2019-04-30 17:47:18 +01:00 Authoring application: mPDF 5.7
MD5: a6fde916e1fb8287aaac675920c80cc9 SHA-1: 747cb3d7e72feba3602d3fe27ede2ca59d43317b SHA-256: 37d171d0f8414124e20e4be7835ce0dce3b69c9d0c93ceb2555294fbb6a769e8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic, which likely serve as a lure to download further content. The primary attack pattern involves directing users to external URLs disguised as legitimate documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9006

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5092093096095094/Ghostly-Images-A-Harper-Harlow-Mystery-5-by-Lily-Harper-Hart.pdf
    • http://loaminoo.linkpc.net/2099099090093096/The-Landlady-s-Girl-by-Rikki-de-la-Vega.pdf
    • http://loaminoo.linkpc.net/7095095097097094/A-Harper-Christmas-Sloane-Harper-2-5-by-Astrid-Arditi.pdf
    • http://loaminoo.linkpc.net/1098090095093099/Rikki-Tikki-Tavi-by-Rudyard-Kipling.pdf
    • http://loaminoo.linkpc.net/4096099091093094/The-Complete-Butcher-s-Tales-by-Rikki-Ducornet.pdf
    • http://loaminoo.linkpc.net/8096094090093/Rikki-Tikki-Tavi-by-Rudyard-Kipling.pdf
    • http://loaminoo.linkpc.net/2099093098099090/Jumpers-by-Norm-Applegate.pdf
    • http://loaminoo.linkpc.net/1092091097094096/The-New-Norm-by-Nakedi-Mbabama.pdf
    • http://loaminoo.linkpc.net/4090093091092095/Shockwave-by-Norm-Applegate.pdf
    • http://loaminoo.linkpc.net/4090093097091096/The-prisoner-by-Norm-Applegate.pdf
    • http://loaminoo.linkpc.net/2099099092090099/Bridget-s-Calling-Free-Spirits-2-by-Rikki-de-la-Vega.pdf
    • http://loaminoo.linkpc.net/2099098098097096/Hannah-s-Healing-Free-Spirits-3-by-Rikki-de-la-Vega.pdf
    • http://loaminoo.linkpc.net/2090094091096096/The-Frog-Who-Would-Be-Prince-by-Norm-DaPloom.pdf
    • http://loaminoo.linkpc.net/2094093090097094/The-Saladin-Strategy-by-Norm-Clark.pdf
    • http://loaminoo.linkpc.net/7097094092091093/Complete-Trash-by-Norm-Crampton.pdf
    • http://loaminoo.linkpc.net/5096092099097095/May-Be-Contagious-The-World-of-Norm-5-by-Jonathan-Meres.pdf
    • http://loaminoo.linkpc.net/5096092098098096/May-Cause-Irritation-The-World-of-Norm-2-by-Jonathan-Meres.pdf
    • http://loaminoo.linkpc.net/1091096092092090093/In-Search-of-the-Past-Stacey-Scott-and-Shane-McLeod-2-by-Rikki-M-Dyson.pdf
    • http://loaminoo.linkpc.net/7097094090095094/Green-House-Eco-Friendly-Disposal-and-Recycling-at-Home-by-Norm-Crampton.pdf
    • http://loaminoo.linkpc.net/2092095097097097/Sharing-Harper-Sharing-Harper-1-by-V-Murphy.pdf