Malicious PDF — malware analysis report

Static analysis result for SHA-256 42f09019d3811e18…

MALICIOUS

PDF

20.6 KB Created: 2019-04-30 03:58:25 +01:00 Authoring application: mPDF 5.7
MD5: 27ef75210d8a472807a5dc2d03cb7af7 SHA-1: 0438ce2a368ffa07e4fcbaabaf8bf2fac9df7229 SHA-256: 42f09019d3811e18f8e0428e95605a41ce0dcfbe90805ce6c1d360bd210f9f0a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic, which is a common technique for distributing malicious content or leading users to phishing sites. The embedded URLs, while currently marked as benign, are part of a pattern designed to lure users into clicking through to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4096090092090094/The-Case-of-Beasts-Explore-the-Film-Wizardry-of-Fantastic-Beasts-and-Where-to-Find-Them-by-Mark-Salisbury.pdf
    • http://loaminoo.linkpc.net/4096096096090/Fantastic-Beasts-and-Where-to-Find-Them-The-Original-Screenplay-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/1091098091091091092/Fantastic-Beasts-and-Where-to-Find-Them-Het-Complete-Filmscenario-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/1094090098096094/Quidditch-Through-the-Ages-amp-Fantastic-Beasts-and-Where-to-Find-Them-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/5090095090095092/Fantastic-Beasts-and-Where-to-Find-Them-Magical-Movie-Handbook-by-Michael-Kogge.pdf
    • http://loaminoo.linkpc.net/5096098095096093/Fantastic-Beasts-and-Where-to-Find-Them-The-Tales-of-Beedle-the-Bard-and-Quidditch-Through-the-Ages-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/3091098096097097/Fantastic-Fabulous-Creatures-amp-Beasts-Vol-2-by-Melanie-Dellas.pdf
    • http://loaminoo.linkpc.net/9094097098098/Fantastic-Fabulous-Creatures-amp-Beasts-by-Melanie-Dellas.pdf
    • http://loaminoo.linkpc.net/9091098092/Fantastic-Beasts-The-Crimes-of-Grindelwald---The-Original-Screenplay-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/3095098099090095/If-You-Find-This-Letter-My-Journey-to-Find-Purpose-Through-Hundreds-of-Letters-to-Strangers-by-Hannah-Brencher.pdf
    • http://loaminoo.linkpc.net/5097091095099091/Find-Faith-Bible-NIV-Verselight-Quickly-Find-Verses-about-God-s-Constant-Faithfulness-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/9090092096090093/101-50-Fantastic-Niall-Horan-Facts-101-Fantastic-One-Direction-Facts-by-Sarah-Jessen.pdf
    • http://loaminoo.linkpc.net/4099094097090/Acceptance-A-Legendary-Guidance-Counselor-Helps-Seven-Kids-Find-the-Right-Colleges-and-Find-Themselves-by-David-L-Marcus.pdf
    • http://loaminoo.linkpc.net/1090090098090090/To-Renew-America-by-Newt-Gingrich.pdf
    • http://loaminoo.linkpc.net/4092098093095099/A-Contract-with-the-Earth-by-Newt-Gingrich.pdf
    • http://loaminoo.linkpc.net/4095096097097095/Newtisms-Wit-and-Wisdom-of-Newt-Gingrich-by-Geoff-Rodkey.pdf
    • http://loaminoo.linkpc.net/3092093091091091/Winning-the-Future-A-21st-Century-Contract-With-America-by-Newt-Gingrich.pdf
    • http://loaminoo.linkpc.net/2092092096099092/Rediscovering-God-in-America-Reflections-on-the-Role-of-Faith-in-Our-Nation-s-History-and-Future-by-Newt-Gingrich.pdf
    • http://loaminoo.linkpc.net/2099099099098095/The-Book-of-Beasts-by-E-Nesbit.pdf
    • http://loaminoo.linkpc.net/4099096095090/Beasts-of-New-York-by-Jon-Evans.pdf
    • http://loaminoo.linkpc.net/5096098095096093/Fantastic-Beasts-and-Where-to-Find-Them-The-Tales-of-Beedle-the-Bard-