Malicious PDF — malware analysis report

Static analysis result for SHA-256 481182d7e3333924…

MALICIOUS

PDF

16.2 KB Created: 2019-05-02 05:27:09 +01:00 Authoring application: mPDF 5.7
MD5: a275077910ec84fda4b3f199e9837c74 SHA-1: 202268a0a48140158a5974ca83c989e1fa05d594 SHA-256: 481182d7e33339243c070a42408a7e2782b222cb5a17e9c192c54192640716a3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. While the specific content of the links appears benign, the sheer volume and the ML classifier's high confidence indicate a malicious intent, likely to direct users to malicious sites or to manipulate search engine rankings. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098096094092096/Legal-Tender-Art-Series-4-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/3093092099094094/Legal-Tender-Bottled-Up-8-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/4096099098098094/Legal-Artistry-Art-Series-1-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/2098096091096094/Legal-Tender-Rosato-amp-Associates-2-by-Lisa-Scottoline.pdf
    • http://loaminoo.linkpc.net/3093093092097096/Love-Means-Renewal-Love-Means-Series-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/2098097095094091/To-Have-Hold-and-Let-Go-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/2098097095095097/Love-in-War-Satyr-1-5-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/3094090094097091/Heart-Unseen-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/7090093094099098/Deanna-Raybourn-Books-2017-Checklist-Reading-Order-of-A-Spear-of-Summer-Grass-Series-City-of-Jasmine-Series-Lady-Julia-Grey-Series-Veronica-Speedwell-Series-and-List-of-All-Deanna-Raybourn-Books-by-Platinum-List.pdf
    • http://loaminoo.linkpc.net/2097097095097091/Love-Comes-Silently-Senses-1-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/3093099095091093/Crunch-Time-Work-Out-4-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/2095096093097091/A-Wild-Ride-The-Bullriders-1-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/3093093092099092/A-Daring-Ride-The-Bullriders-2-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/4096099098097091/Love-Comes-in-Darkness-Senses-2-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/2095097098096091/Inside-Out-Bronco-s-Boys-1-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/4093092092091097/Personal-Training-Work-Out-6-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/4091098095096090/Love-Comes-To-Light-Senses-6-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/3093092099094096/Artistic-Pursuits-Bottled-Up-7-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/4096098091094093/Inside-Out-Bronco-s-Boys-1-by-Andrew-Grey.pdf
    • http://loaminoo.linkpc.net/2098092092098094/Fifty-Shames-of-Earl-Grey-by-Andrew-Shaffer.pdf
    • http://loaminoo.linkpc.net/20