Malicious PDF — malware analysis report

Static analysis result for SHA-256 4835bbeeb0a98d45…

MALICIOUS

PDF

20.1 KB Created: 2019-04-30 02:26:41 +01:00 Authoring application: mPDF 5.7
MD5: b29e0ce457b4153c510f47cf7918d73e SHA-1: 8101aa1d50dfc90108694c97aee75a17679dbc81 SHA-256: 4835bbeeb0a98d4564cdc0cf74ad208714cd8b4b2d30cbc4f54f12f6b941f44a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, a technique often used for SEO manipulation or to redirect users to potentially malicious websites. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. No scripts were extracted from this sample, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4095090093099091/Gordon-a-Tale-of-Heartbreak-and-Adventure-by-Smiley-Blackmore.pdf
    • http://loaminoo.linkpc.net/8094097099093/The-Tell-Tale-Start-by-Gordon-McAlpine.pdf
    • http://loaminoo.linkpc.net/1092092092094097/A-Cobbler-s-Tale-by-Neil-Perry-Gordon.pdf
    • http://loaminoo.linkpc.net/1097096098092098/Popstars-Friends-amp-Lovers-a-dreamer-s-tale-by-Karen-Gordon.pdf
    • http://loaminoo.linkpc.net/5099090096095092/Here-Come-the-Girl-Scouts-The-Amazing-All-True-Story-of-Juliette-Daisy-Gordon-Low-and-Her-Great-Adventure-by-Shana-Corey.pdf
    • http://loaminoo.linkpc.net/5097097091097095/Dark-Wind-A-Survivor-s-Tale-of-Love-and-Loss-by-Gordon-Chaplin.pdf
    • http://loaminoo.linkpc.net/7096090090090098/The-Key-to-Skandos-A-tale-of-adventure-love-and-magic-by-William-A-Prater.pdf
    • http://loaminoo.linkpc.net/8096098090091090/Michael-and-Ava-s-Louisiana-Adventure-A-Tale-about-the-Dangers-of-Littering-by-Shelle-Buras.pdf
    • http://loaminoo.linkpc.net/9094093095090091/Hawaiian-Heartbreak-Hawaiian-Heartbreak-1-by-Libby-Cole.pdf
    • http://loaminoo.linkpc.net/1091094097098092/Black-Livingstone-A-True-Tale-of-Adventure-in-the-Nineteenth-Century-Congo-by-Pagan-Kennedy.pdf
    • http://loaminoo.linkpc.net/5095099092097/The-Princess-Bride-S-Morgenstern-s-Classic-Tale-of-True-Love-and-High-Adventure-by-William-Goldman.pdf
    • http://loaminoo.linkpc.net/8094092092092097/1692-Pirate-Dawn-A-tale-of-treachery-betrayal-and-high-seas-adventure-by-Wynford-Emanuel.pdf
    • http://loaminoo.linkpc.net/3095093093091091/The-Princess-Bride-S-Morgenstern-s-Classic-Tale-of-True-Love-and-High-Adventure-by-William-Goldman.pdf
    • http://loaminoo.linkpc.net/6096090093092/Piratica-Being-a-Daring-Tale-of-a-Singular-Girl-s-Adventure-Upon-the-High-Seas-Piratica-1-by-Tanith-Lee.pdf
    • http://loaminoo.linkpc.net/6099099094090097/The-Princess-Bride-S-Morgenstern-s-Classic-Tale-of-True-Love-and-High-Adventure-The-quot-Good-Parts-quot-Version-by-William-Goldman.pdf
    • http://loaminoo.linkpc.net/2097098093093098/Lorna-Doone-by-R-D-Blackmore.pdf
    • http://loaminoo.linkpc.net/3091099091097095/The-One-Who-Would-Be-King-by-Gareth-Blackmore.pdf
    • http://loaminoo.linkpc.net/3096090095091095/Well-Fed-Mountain-Man-4-by-Keith-C-Blackmore.pdf
    • http://loaminoo.linkpc.net/2092094093090094/Elementary-Erotica-by-J-Blackmore.pdf
    • http://loaminoo.linkpc.net/9099091093098091/Night-of-the-Bonfire-by-Jane-Blackmore.pdf