Malicious PDF — malware analysis report

Static analysis result for SHA-256 3b37474183d4b712…

MALICIOUS

PDF

17.1 KB Created: 2019-05-02 17:14:43 +01:00 Authoring application: mPDF 5.7
MD5: b88e45648919a01c906534a8d1c52975 SHA-1: 9c4ede2e17414805ca9c3719d1dcd5de2fd0f3d0 SHA-256: 3b37474183d4b7121ad1e8e5dc8ec599dfe26a6dc2aad5374054172d584c5eaf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to book titles and are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6095090097097095/The-Right-Bride-Bride-of-Desire-The-English-Aristocrat-s-Bride-Vacancy-Wife-of-Convenience-by-Sara-Craven.pdf
    • http://loaminoo.linkpc.net/6095090097095096/The-English-Aristocrat-s-Bride-by-Masako-Sone.pdf
    • http://loaminoo.linkpc.net/2090093094090096/The-Forced-Bride-by-Sara-Craven.pdf
    • http://loaminoo.linkpc.net/6094092096095093/His-Forbidden-Bride-by-Sara-Craven.pdf
    • http://loaminoo.linkpc.net/4098099097099/The-Brides-Trilogy-A-3-In-1-Edition-Including-The-Sherbrooke-Bride-The-Hellion-Bride-And-The-Heiress-Bride-by-Catherine-Coulter.pdf
    • http://loaminoo.linkpc.net/1090091093095096095/Mollie-Bride-of-Georgia-American-Mail-Order-Bride-4-by-Lorrie-Farrelly.pdf
    • http://loaminoo.linkpc.net/2090090090097095/His-Jilted-Bride-Banks-Brothers-Bride-3-by-Rose-Gordon.pdf
    • http://loaminoo.linkpc.net/6095090090090091/An-Improper-Bride-Elliot-amp-Annabelle-2-Billionaires-Brides-of-Convenience-4-by-Nadia-Lee.pdf
    • http://loaminoo.linkpc.net/3096098099096091/Barefoot-Bride-for-Three-Bride-Train-1-by-Reece-Butler.pdf
    • http://loaminoo.linkpc.net/6099091093095090/The-Highlander-s-Reluctant-Bride-The-Highlander-s-Bride-2-by-Cathy-MacRae.pdf
    • http://loaminoo.linkpc.net/4093091097098090/The-Tale-Of-The-Vampire-Bride-Vampire-Bride-1-by-Rhiannon-Frater.pdf
    • http://loaminoo.linkpc.net/2090093092098093/Captive-in-the-Spotlight-Blackmailed-Bride-Innocent-Wife-by-Annie-West.pdf
    • http://loaminoo.linkpc.net/4092095093097092/The-Tempted-Bride-An-Erotic-Cheating-Wife-Tale-by-Anne-Hedonia.pdf
    • http://loaminoo.linkpc.net/4093094095092090/An-English-Bride-In-Scotland-Highland-Brides-1-by-Lynsay-Sands.pdf
    • http://loaminoo.linkpc.net/2096090099096099/An-English-Bride-In-Scotland-Highland-Brides-1-by-Lynsay-Sands.pdf
    • http://loaminoo.linkpc.net/9090095097090/An-English-Bride-In-Scotland-Highland-Brides-1-by-Lynsay-Sands.pdf
    • http://loaminoo.linkpc.net/3090096092092098/A-Bride-s-Story-Vol-3-A-Bride-s-Story-3-by-Kaoru-Mori.pdf
    • http://loaminoo.linkpc.net/6094092096095091/Wife-Against-Her-Will-by-Sara-Craven.pdf
    • http://loaminoo.linkpc.net/4090093093098/The-Dark-God-s-Bride-The-Dark-God-s-Bride-2-by-Dahlia-Lu.pdf
    • http://loaminoo.linkpc.net/8095092098092098/Fox-s-Bride-by-A-E-Marling.pdf
    • http://loaminoo.linkpc.net/6095090090090091/An-Improper-Bride-Elliot-amp-Annabelle-2-Billionaires-Brides-of-Conveni