Malicious PDF — malware analysis report

Static analysis result for SHA-256 6e49f2ab4964fd14…

MALICIOUS

PDF

14.7 KB Created: 2019-05-01 19:55:25 +01:00 Authoring application: mPDF 5.7
MD5: ab8bb134fdaf05836abc3c53314f4e03 SHA-1: 70e24bd857963b255d58d86a2ed24ea639d32210 SHA-256: 6e49f2ab4964fd14641997833e46b32d1e2a2e313fa241d9b15149f7eb3e1c7e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier and contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096094090090096/The-Constant-Princess-The-Plantagenet-and-Tudor-Novels-6-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/4095091091093091/The-Boleyn-Inheritance-The-Plantagenet-and-Tudor-Novels-10-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/2099096096094090/The-Other-Boleyn-Girl-The-Plantagenet-and-Tudor-Novels-9-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/3096090095098096/The-Virgin-s-Lover-The-Plantagenet-and-Tudor-Novels-13-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/3091093097095098/The-Kingmaker-s-Daughter-The-Plantagenet-and-Tudor-Novels-4-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/3092099095095095/Three-Sisters-Three-Queens-The-Plantagenet-and-Tudor-Novels-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/1091097095092094090/Jen-jedna-bude-kr-lovnou-The-Plantagenet-and-Tudor-Novels-4-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/5094096094094093/Trei-Surori-Trei-Regine-The-Plantagenet-and-Tudor-Novels-8-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/1091090099092096091/The-Constant-Princess-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/3098092097098098/The-Constant-Princess-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/4095094098094097/The-Constant-Princess-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/8095099094096097/The-Queen-s-Fool-The-Tudor-Court-4-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/3092098091095095/The-Other-Boleyn-Girl-The-Tudor-Court-3-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/3093099092092094/Plantagenet-Princess-Tudor-Queen-The-Story-of-Elizabeth-of-York-by-Samantha-Wilcoxson.pdf
    • http://loaminoo.linkpc.net/1091091098090097090/The-Other-Queen-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/3095093099091096/The-Red-Queen-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/4091097090095092/The-Little-House-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/7095093091094091/The-Virgin-s-Lover-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/3097097091099092/The-Lady-of-the-Rivers-by-Philippa-Gregory.pdf
    • http://loaminoo.linkpc.net/7096095099093098/La-sesta-moglie-by-Philippa-Gregory.pdf