Malicious PDF — malware analysis report

Static analysis result for SHA-256 44f48699ca3a74b7…

MALICIOUS

PDF

16.9 KB Created: 2019-05-01 17:11:08 +01:00 Authoring application: mPDF 5.7 First seen: 2021-10-11
MD5: 4fc75a9b0c07ead58ecf1846d9b81e27 SHA-1: 87e80595c4449c0804b49290782e4e254f154ad5 SHA-256: 44f48699ca3a74b7e0544e992028db7b5a00e8c15950b4f0671a80da8caa8e37
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, suggesting a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the sheer volume of links and the heuristic firing indicate a malicious intent to direct users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4090092092091092/Amanda-in-Alberta-The-Writing-on-the-Stone-Amanda-Travels-4-by-Darlene-Foster.pdf In PDF document text
    • http://loaminoo.linkpc.net/4095094097093095/Amanda-in-Alberta-The-Writing-on-the-Stone-by-Darlene-Foster.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4090092092091097/Amanda-in-Arabia-The-Perfume-Flask-by-Darlene-Foster.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3090095099091/Chasing-Amanda-by-Melissa-Foster.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7093095090090090/Shattered-The-Amanda-Project-3-by-Amanda-Valentino.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2090092092098097/Love-Lies-amp-Mystery-Come-Back-to-Me-Chasing-Amanda-Megan-s-Way-by-Melissa-Foster.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2093094091099093/The-Adventures-of-Cole-and-Perry-by-Amanda-C-Stone.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1096092094092091/Amanda-Lester-and-the-Orange-Crystal-Crisis-Amanda-Lester-Detective-2-by-Paula-Berinstein.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9092091099091097/Amanda-Seyfried-173-Success-Facts---Everything-you-need-to-know-about-Amanda-Seyfried-by-Jimmy-Barnett.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9092091099091090/Amanda-Seyfried-173-Success-Facts---Everything-You-Need-to-Know-about-Amanda-Seyfried-by-Jimmy-Barnett.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9092091098090097/The-Amanda-Seyfried-Handbook---Everything-You-Need-to-Know-about-Amanda-Seyfried-by-Antonio-Serrano.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4094093097099091/DC-Comics-The-Sequential-Art-of-Amanda-Conner-by-Amanda-Conner.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1099098096096096/Princess-for-a-Summer-An-Amanda-Clarke-Novel-by-Amanda-Clarke.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8092091093090092/Travels-in-Persia-1627-1629-by-Thomas-Herbert-Foster.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7096095090092/I-d-Like-by-Amanda-Michalopoulou.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4098095098094/Amanda-by-Kay-Hooper.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1097095090098094/Heir-to-the-Sky-by-Amanda-Sun.pdfIn PDF document text
    • http://loaminoo.linkpc.net/5090090098090094/Amanda-by-Kay-Hooper.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1097093099092096/Always-by-Amanda-Weaver.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2099095099093097/Something-More-by-Amanda-Young.pdfIn PDF document text