Malicious PDF — malware analysis report

Static analysis result for SHA-256 42f6ec1963a672a3…

MALICIOUS

PDF

18.4 KB Created: 2019-05-02 21:08:22 +01:00 Authoring application: mPDF 5.7
MD5: d3127ef3d1a4f3478fa20d2e87d9b032 SHA-1: 80156c19ca751890a531f185840f49123ca73e03 SHA-256: 42f6ec1963a672a3ee4c1324fb143fe32aa65ecb733876f4c2c54c59a8f15ea2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, forming a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern observed is the distribution of a large number of SEO-optimized PDF links, likely intended to drive traffic to malicious or deceptive content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4091094098096093/Hometown-Girls-Reunion-Hometown-Girls-Series-Book-2-by-Tressa-Messenger.pdf
    • http://loaminoo.linkpc.net/2097091095098096/Hometown-Star-Hometown-Alaska-Men-1-by-Joleen-James.pdf
    • http://loaminoo.linkpc.net/4091094098098091/Hometown-Heartbreaker-Hometown-Alaska-Men-3-by-Joleen-James.pdf
    • http://loaminoo.linkpc.net/3094099091092/Hometown-Girl-After-All-Hometown-2-by-Kirsten-Fullmer.pdf
    • http://loaminoo.linkpc.net/2091091092095/Unexpected-Son-Hometown-Reunion-1-by-Marisa-Carroll.pdf
    • http://loaminoo.linkpc.net/4099092098096096/Hometown-Holiday-Reunion-Oaks-Crossing-3-by-Mia-Ross.pdf
    • http://loaminoo.linkpc.net/2090098096097097/The-Girls-Book-3-Even-More-Ways-To-Be-The-Best-At-Everything-Girls-Book-by-Tracey-Turner.pdf
    • http://loaminoo.linkpc.net/4091099091098094/--LOST-GIRLS-1-Shingeki-no-Kyojin-Lost-Girls-1-Attack-on-Titan-Lost-Girls-Manga-1-by-Hajime-Isayama.pdf
    • http://loaminoo.linkpc.net/7091092099091091/Goth-Girls-Don-t-Taste-Like-Chicken-Me-and-My-Friend-Maddie-Gothic-Book-Series-1-by-Robert-Tomoguchi.pdf
    • http://loaminoo.linkpc.net/4095097093099/Hometown-by-Marsha-Qualey.pdf
    • http://loaminoo.linkpc.net/1098092097091/The-Hometown-by-Leena-Ceraveeni.pdf
    • http://loaminoo.linkpc.net/3091092090098099/Girls-to-the-Rescue-Book-4-Girls-to-the-Rescue-4-by-Bruce-Lansky.pdf
    • http://loaminoo.linkpc.net/3091091092096096/Girls-to-the-Rescue-Book-5-Girls-to-the-Rescue-5-by-Bruce-Lansky.pdf
    • http://loaminoo.linkpc.net/1090092098093098090/Julie-Garwood-Reading-List---The-Girls-of-Canby-Hall-Series-Crown-s-Spies-Series-Lairds-Brides-Series-Highlands-Lairds-Series-Clayborne-of-Rosehill-Series-etc-by-Edward-Peterson.pdf
    • http://loaminoo.linkpc.net/4097092092093095/A-Case-of-Hometown-Blues-by-W-S-Gager.pdf
    • http://loaminoo.linkpc.net/5090099092093098/Hometown-for-an-Hour-by-Jennifer-Rose.pdf
    • http://loaminoo.linkpc.net/3097095092098094/Hometown-Legend-by-Jerry-B-Jenkins.pdf
    • http://loaminoo.linkpc.net/6096091093099/His-Hometown-Girl-by-Karen-Rock.pdf
    • http://loaminoo.linkpc.net/8091093098097099/The-Best-Bride-Hometown-Heartbreakers-1-by-Susan-Mallery.pdf
    • http://loaminoo.linkpc.net/7091093096092099/The-Hometown-Squad-The-Beginning-by-Mary-Grasse.pdf
    • http://loaminoo.linkpc.net/4091099091098094/--LOST-GIRLS-1-Shingeki-no-Kyojin-Lost-Girls-1-Attack-on-Titan-Lost-Girls-Manga-1-b