Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b1401909e2545db…

MALICIOUS

PDF

17.7 KB Created: 2019-05-01 16:18:42 +01:00 Authoring application: mPDF 5.7
MD5: e40bd64ba3c8ac054d058d6276bf7730 SHA-1: 93d12ced715a66fbd11b6c1716babf1bb157e2eb SHA-256: 4b1401909e2545dbc3aa051d879ee10f7372ecdb8b15f8d72b627c70dc725893
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO manipulation tactic. While the document body is heavily obfuscated, the presence of numerous links points towards a malicious intent to redirect users. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096096093095091/Victory-Rising-Heroes-and-Rogues-2-by-Destiny-Blaine.pdf
    • http://loaminoo.linkpc.net/3095098091091099/Sassy-Road-Heroes-and-Rogues-1-by-Destiny-Blaine.pdf
    • http://loaminoo.linkpc.net/4095096097091098/Autumn-Lake-Heroes-and-Rogues-4-by-Destiny-Blaine.pdf
    • http://loaminoo.linkpc.net/6095097095096/Rogues-amp-Heroes-of-the-Island-of-Newfoundland-by-Paul-Butler.pdf
    • http://loaminoo.linkpc.net/1097098090091/A-Pyrrhic-Victory-Volume-1-the-Shaping-of-Destiny-by-Ian-Crouch.pdf
    • http://loaminoo.linkpc.net/5093097096098/Road-Work-Among-Tyrants-Heroes-Rogues-and-Beasts-by-Mark-Bowden.pdf
    • http://loaminoo.linkpc.net/8091096096098/Three-Novels-of-World-War-II-The-Rising-Tide-The-Steel-Wave-No-Less-Than-Victory-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/7090091093098091/Destiny-Calls-The-Phoenix-Rising-1-by-Phenice-Arielle.pdf
    • http://loaminoo.linkpc.net/4097096091096096/The-Chronicles-of-Darius-Slave-Rising-Dagger-of-Destiny-1-by-Jess-Thomas.pdf
    • http://loaminoo.linkpc.net/3097095097098090/Victory-Run-1-The-Story-of-Victory-Payne-1-by-Devon-Hartford.pdf
    • http://loaminoo.linkpc.net/9098094091090/Uncommon-Heroes-A-Celebration-of-Heroes-and-Role-Models-for-Gay-and-Lesbian-Americans-by-Jeane-Manford.pdf
    • http://loaminoo.linkpc.net/1090093099093095/Galen-Beknighted-Dragonlance-Heroes-6-Heroes-II-3-by-Michael-Williams.pdf
    • http://loaminoo.linkpc.net/3093094092093097/The-New-Heroes-Superhuman-New-Heroes-Quantum-Prophecy-3-5-by-Michael--Carroll.pdf
    • http://loaminoo.linkpc.net/1090093098090090/The-Gates-of-Thorbardin-Dragonlance-Heroes-5-Heroes-II-2-by-Dan-Parkinson.pdf
    • http://loaminoo.linkpc.net/1090093098097091/Kaz-the-Minotaur-Dragonlance-Heroes-4-Heroes-II-1-by-Richard-A-Knaak.pdf
    • http://loaminoo.linkpc.net/3091099090092093/Darkness-Rising-Complete-Trilogy-Collection-The-Gathering-The-Calling-The-Rising-by-Kelley-Armstrong.pdf
    • http://loaminoo.linkpc.net/3095095099091090/Blair-s-Destiny-The-Destiny-Trilogy-Book-2-by-Miranda-Lynn.pdf
    • http://loaminoo.linkpc.net/1095090095097091/Destiny-s-Plan-Destiny-s-Series-1-by-Victoria-Saccenti.pdf
    • http://loaminoo.linkpc.net/4097096095093095/Midwife-to-Destiny-Destiny-Series-1-by-Nana-Prah.pdf
    • http://loaminoo.linkpc.net/4090095096093090/Destiny-s-Foreshore-Destiny-Series-Book-1-by-Mel-Woodall.pdf
    • http://loaminoo.linkpc.net/3097095097098090/Victory-Run-1-The-Story-o