Malicious PDF — malware analysis report

Static analysis result for SHA-256 7006379dd92b0e4e…

MALICIOUS

PDF

16.6 KB Created: 2019-05-02 00:17:41 +01:00 Authoring application: mPDF 5.7
MD5: cb1bb7a3568ee2cd75735d2702ae6813 SHA-1: e265f6c7430681decf43cdc1b44870e62ea81a7f SHA-256: 7006379dd92b0e4e9a176a2bdc119860ab56bbb2b38e0028c8ad48d1a9e0fccf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to redirect users to potentially harmful content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092094092092091/Alpha-Series-Alpha-Malik-by-Midika-Crane.pdf
    • http://loaminoo.linkpc.net/1091091098096090091/Ladylust-4-Alpha-Males-The-Big-Bundle-of-Hetero-Erotica-About-Macho-Alpha-Studs-Alpha-Male-Hetero-Big-Bundles-Book-6-by-B-R-Eastman.pdf
    • http://loaminoo.linkpc.net/2090097098095095/Charming-The-Alpha-The-Crane-Curse-1-by-Liliana-Rhodes.pdf
    • http://loaminoo.linkpc.net/1094097091092092/Billionaire-Romance-Complete-Series-Alpha-Male-Romances-Suspenseful-Alpha-Male-Billionaire-Bad-Boy-Romance-Billionaire-Series-by-J-L-Ryan.pdf
    • http://loaminoo.linkpc.net/4099091097091095/Alpha-Wolf-Alpha-Force-2-by-Linda-O-Johnston.pdf
    • http://loaminoo.linkpc.net/9096092098091092/Elizabeth-Alpha-of-Dragons-RH-Fated-Alpha-4-by-Ava-Mason.pdf
    • http://loaminoo.linkpc.net/1091097091090098/Avoiding-Alpha-Alpha-Girl-2-by-Aileen-Erin.pdf
    • http://loaminoo.linkpc.net/3098093090098099/The-Alpha-s-Hunger-The-Alpha-s-Doms-1-by-Renee-Rose.pdf
    • http://loaminoo.linkpc.net/1091098098093099095/Alpha-Enticing-Fallen-Alpha-3-by-Rebecca-Royce.pdf
    • http://loaminoo.linkpc.net/4096099099091099/Christmas-Alpha-Alpha-1-by-Carole-Mortimer.pdf
    • http://loaminoo.linkpc.net/3097091098091096/Being-Alpha-Alpha-Girl-7-by-Aileen-Erin.pdf
    • http://loaminoo.linkpc.net/4095092091091092/The-Alpha-s-Toy-The-Alpha-Shifter-Collection-1-by-Sam-Crescent.pdf
    • http://loaminoo.linkpc.net/3098096094090099/Alpha-Alpha-1-by-Jasinda-Wilder.pdf
    • http://loaminoo.linkpc.net/2090097098095097/Curse-of-the-Alpha-The-Complete-Bundle-Curse-of-the-Alpha-serial-1-6-by-Tasha-Black.pdf
    • http://loaminoo.linkpc.net/4096093095091092/Thrust-The-Alpha-Escort-Series-1-by-Sybil-Bartel.pdf
    • http://loaminoo.linkpc.net/1099090092091096/Rough-The-Alpha-Escort-Series-2-by-Sybil-Bartel.pdf
    • http://loaminoo.linkpc.net/2094099091098098/Ruined-Loving-An-Alpha-Male-Series-1-by-S-K-Lessly.pdf
    • http://loaminoo.linkpc.net/2099094091097096/A-is-for-Alpha-Male-A-is-for-Alpha-Male-1-by-Laurel-Ulen-Curtis.pdf
    • http://loaminoo.linkpc.net/4098097099097091/True-Alpha-Complete-Box-Set-True-Alpha-1-6-by-Alisa-Woods.pdf
    • http://loaminoo.linkpc.net/1097097096097098/Punished-by-the-Alpha-Poutine-Alpha-Poutine-2-by-Twisty-McCox.pdf