Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b13b5520a052465…

MALICIOUS

PDF

15.8 KB Created: 2019-05-02 02:25:47 +01:00 Authoring application: mPDF 5.7
MD5: 23436697b41b76326963f7cdfc740201 SHA-1: 4de4e17244c10fe6053709eb4f35963e3d621d8f SHA-256: 4b13b5520a05246523c8d1e8e730fcdef55a70284d5ea28077ba9ddd6051ef33
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs were marked as confirmed_benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to manipulate search engine results or redirect users to malicious sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3091096094094091/Wooden-Bones-by-Scott-William-Carter.pdf
    • http://loaminoo.linkpc.net/1093095091095095/Carter-s-Unfocused-One-Track-Mind-Carter-Finally-Gets-It-3-by-Brent-Crawford.pdf
    • http://loaminoo.linkpc.net/1093095099095091/Carter-s-Big-Break-Carter-Finally-Gets-It-2-by-Brent-Crawford.pdf
    • http://loaminoo.linkpc.net/1095098097090094/Altar-Ego-by-Kathy-Lette.pdf
    • http://loaminoo.linkpc.net/4099093095093097/Altar-Call-by-Hope-Lyda.pdf
    • http://loaminoo.linkpc.net/1091095092096094096/The-Altar-and-the-Sacrificed-II-by-Reng-David-D.pdf
    • http://loaminoo.linkpc.net/1096095098092099/Altar-Ed-Plans-by-Rebecca-Talley.pdf
    • http://loaminoo.linkpc.net/3092090092095094/Rush-to-the-Altar-by-Jamie-Carie.pdf
    • http://loaminoo.linkpc.net/1091093093093/Left-at-the-Altar-by-Margaret-Brownley.pdf
    • http://loaminoo.linkpc.net/8099093098099095/Married-In-Montana-At-the-Altar-1-by-Kirsten-Osbourne.pdf
    • http://loaminoo.linkpc.net/7095099097098094/Temporary-Groom-Left-At-The-Altar-1-by-J-S-Scott.pdf
    • http://loaminoo.linkpc.net/3097095096091099/Murder-at-the-Altar-Ellie-Quicke-1-by-Veronica-Heley.pdf
    • http://loaminoo.linkpc.net/6093090096097/The-Dangerous-Lives-of-Altar-Boys-by-Chris-Fuhrman.pdf
    • http://loaminoo.linkpc.net/1090091092090094096/The-Pergamon-Altar-Its-Rediscovery-History-And-Reconstruction-by-Max-Kunze.pdf
    • http://loaminoo.linkpc.net/1090093099090094090/Becoming-Carter-The-Carter-Trilogy-2-by-W-S-Greer.pdf
    • http://loaminoo.linkpc.net/2096097099098098/At-the-Altar-in-Your-Underwear-40-Secrets-to-an-Amazing-Wedding-and-a-Better-You-by-Alexis-Asbe.pdf
    • http://loaminoo.linkpc.net/5099098095096/An-Altar-in-the-World-A-Geography-of-Faith-by-Barbara-Brown-Taylor.pdf
    • http://loaminoo.linkpc.net/3098094094099090/War-Comes-to-Garmser-Thirty-Years-of-Conflict-on-the-Afghan-Frontier-Carter-Malkasian-by-Carter-Malkasian.pdf
    • http://loaminoo.linkpc.net/3093090090093099/City-of-Bones-City-of-Bones-Graphic-Novel-2-by-Mike-Raicht.pdf
    • http://loaminoo.linkpc.net/7095099096097/Angela-Carter-s-Book-of-Fairy-Tales-by-Angela-Carter.pdf
    • http://loaminoo.linkpc.net/3097095096091099/Murder-at-the-Altar-Ellie-Quicke-1-by-Vero