Malicious PDF — malware analysis report

Static analysis result for SHA-256 43e590a83c4b4fbe…

MALICIOUS

PDF

19.0 KB Created: 2019-04-29 23:28:40 +01:00 Authoring application: mPDF 5.7
MD5: 1fb3831e5b4f31c0aee7fc037845626e SHA-1: 93fa5fc55810f702d8e9a1634a9dbfcce3f227d6 SHA-256: 43e590a83c4b4fbebd1a2e22e828305b8dbfc4da81e4d8b688eb7ef3c1169c80
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to other PDF documents, forming a link farm. This technique is often used to artificially inflate search engine rankings or to distribute malicious content indirectly. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3097097091091095/Finn-and-the-Bounty-Hunters-Urban-Affairs-5-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/4092093095093099/Undercover-Lovers-Urban-Affairs-1-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/3090099097096093/Bounty-Hunters-Inc-2-by-Emilia-Watson.pdf
    • http://loaminoo.linkpc.net/1098096092093099/Promises-Part-1-Bounty-Hunters-1-by-A-E-Via.pdf
    • http://loaminoo.linkpc.net/4096092092090095/Promises-The-Next-Generation-Bounty-Hunters-5-by-A-E-Via.pdf
    • http://loaminoo.linkpc.net/2098098093091098/Feeling-The-Heat-Harlequin-Blaze-361-Big-Bad-Bounty-Hunters-by-Rhonda-Nelson.pdf
    • http://loaminoo.linkpc.net/5090091090092097/Off-Limits-Sanctuary-1-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/2096091095094098/Loki-Hybrids-3-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/3095092091093091/Backfire-Southwest-Shifters-3-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/1099092095092094/Some-Like-it-Rough-The-Gentlemen-s-Club-2-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/3095092091092092/Crossfire-Southwest-Shifters-4-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/3095092091092093/Kade-and-the-Captives-Symbiotic-Mates-5-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/3097096099090091/Peter-and-the-Wolf-Symbiotic-Mates-2-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/3095093091097092/Cullen-and-the-Kindred-Spirit-Symbiotic-Mates-7-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/6099095097091090/Urban-Carnivores-Ecology-Conflict-and-Conservation-by-Stanley-D-Gehrt.pdf
    • http://loaminoo.linkpc.net/3096095093090092/Finding-God-in-the-City-Making-Sense-of-an-Urban-World-by-Brad-Stanley.pdf
    • http://loaminoo.linkpc.net/3094090090095093/Star-Wars-Tales-Omnibus-Tales-from-the-Mos-Eisley-Cantina-Tales-of-the-Bounty-Hunters-and-Tales-from-Jabba-s-Palace-by-Kevin-J-Anderson.pdf
    • http://loaminoo.linkpc.net/4096098097094096/Silent-Knights-Knights-1-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/3091090090093091/Bounty-s-End-Bounty-for-Hire-2-by-A-J-Wiliams.pdf
    • http://loaminoo.linkpc.net/6095096093097090/Availability-of-Insurance-in-Milwaukee-Wisconsin-Field-Hearing-Before-the-Subcommittee-on-Consumer-Credit-and-Insurance-of-the-Committee-on-Banking-Finance-and-Urban-Affairs-House-of-Representatives-One-Hundred-Third-Congress-Second-Session-Janua-by-U-S-House-of-Representatives.pdf