Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ae275b417e936c7…

MALICIOUS

PDF

14.7 KB Created: 2019-05-03 00:36:50 +01:00 Authoring application: mPDF 5.7
MD5: cf94b15dbb3197260e70804551367735 SHA-1: 49d01208a1ae59d472d3e26bbb4dd7344a6c0bc2 SHA-256: 4ae275b417e936c71b6510940c812a2a45dca8a96a939f13151ad5e820c10eac
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links, identified as a PDF SEO link farm. The primary purpose appears to be directing users to external content, potentially for phishing or malware distribution, rather than delivering a direct payload within the PDF itself. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4098099092094/Broken-Hart-The-Hart-Family-1-by-Ella-Fox.pdf
    • http://loaminoo.linkpc.net/1094096092096092/The-Hart-Family-Series-Box-Set-Books-1-4-The-Hart-Family-1-4-by-Ella-Fox.pdf
    • http://loaminoo.linkpc.net/4096099094096/Missing-Hart-The-Hart-Family-5-by-Ella-Fox.pdf
    • http://loaminoo.linkpc.net/8092090090093/Unbroken-Hart-The-Hart-Family-4-by-Ella-Fox.pdf
    • http://loaminoo.linkpc.net/1093095093094099/Shattered-Hart-The-Hart-Family-2-by-Ella-Fox.pdf
    • http://loaminoo.linkpc.net/4095097093096093/Finding-Hart-The-Hart-Family-6-by-Ella-Fox.pdf
    • http://loaminoo.linkpc.net/1090093095097095092/Elias-Baby-by-Ella-Hart.pdf
    • http://loaminoo.linkpc.net/4094097099092/Broken-by-Megan-Hart.pdf
    • http://loaminoo.linkpc.net/2091094099090099/Broken-by-Megan-Hart.pdf
    • http://loaminoo.linkpc.net/1098095094091098/Shadow-of-the-Titanic-A-Survivor-s-Story-a-Biography-of-Miss-Eva-Hart-by-Eva-Hart.pdf
    • http://loaminoo.linkpc.net/9091094092092098/Wenn-es-hart-auf-hart-kommt-by-Ben-Horowitz.pdf
    • http://loaminoo.linkpc.net/4094090094091092/The-Broken-Warrior-Navy-SEAL-Romances-by-Taylor-Hart.pdf
    • http://loaminoo.linkpc.net/1097093097092090/Need-The-MacKenzie-Family-12-by-Liliana-Hart.pdf
    • http://loaminoo.linkpc.net/2098095091091092/Scorch-The-MacKenzie-Family-11-by-Liliana-Hart.pdf
    • http://loaminoo.linkpc.net/2090092090099098/Cade-The-MacKenzie-Family-5-by-Liliana-Hart.pdf
    • http://loaminoo.linkpc.net/4097095091091098/Secrets-and-Satin-The-MacKenzie-Family-7-by-Liliana-Hart.pdf
    • http://loaminoo.linkpc.net/1094098091099092/The-MacKenzies-Happily-Ever-After-The-MacKenzie-Family-1-5-2-5-3-5-4-5-by-Liliana-Hart.pdf
    • http://loaminoo.linkpc.net/5092098094095096/Wyoming-Sweethearts-Granger-Family-Ranch-6-by-Jillian-Hart.pdf
    • http://loaminoo.linkpc.net/5092098094095091/The-Soldier-s-Holiday-Vow-Granger-Family-Ranch-2-by-Jillian-Hart.pdf
    • http://loaminoo.linkpc.net/6094093090095099/Sins-and-Scarlet-Lace-The-MacKenzie-Family-8-by-Liliana-Hart.pdf
    • http://loaminoo.linkpc.net/4094090094091092/The-Broken-Warrior-Navy-SEAL-Romances-by-Taylor