Malicious PDF — malware analysis report

Static analysis result for SHA-256 731790756e55407f…

MALICIOUS

PDF

19.0 KB Created: 2019-05-07 04:25:20 +01:00 Authoring application: mPDF 5.7
MD5: 9168863c995c2bb87d215f340a445a7e SHA-1: e30da7dde85610b36f85f429bf48622e6a97aae3 SHA-256: 731790756e55407f1cafa2e57f5d6eff8317f76a1e256903eb868c16f0ac3057
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6094099091099094/Unsurpassed-No-Rival-1-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/4098093097092091/Undone-Hooked-1-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/2097099099096093/A-Splash-of-Hope-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/2091098097091093/The-Society-of-Sinners-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/6094099092090096/Bryant-Undefeated-1-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/4093093092096095/Unbound-Fantasies-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/6094099091098098/Clinch-Low-Blow-1-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/4091094095097096/Unequaled-No-Rival-3-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/6094099091099092/Blow-Hard-Hit-2-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/3090090094097099/Sarah-s-Dirty-Secret-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/4091098094098096/The-Assassin-Safe-Haven-3-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/4096090090099097/Paul-Undefeated-series-book-4-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/4096090090099096/Walt-Undefeated-series-book-3-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/3090098099098092/The-Sexy-amp-The-Undead-Sexy-Witches-1-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/3090090095092094/Being-his-Favorite-Favorite-Things-1-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/6094099091094094/Merciless-Charity-Charity-Styles-1-by-Wayne-Stinnett.pdf
    • http://loaminoo.linkpc.net/6094099091099099/Charity-s-Passion-Charity-3-by-Maya-James.pdf
    • http://loaminoo.linkpc.net/1091096093092098090/Publick-Education-Particularly-in-the-Charity-Schools-a-Sermon-Preach-d-at-St-Philip-s-Church-in-Birmingham-August-9-1724-at-the-Opening-of-a-Charity-School-Built-to-Receive-an-Hundred-Children-by-Thomas-Bisse.pdf
    • http://loaminoo.linkpc.net/1091096093092098097/Publick-education-particularly-in-the-charity-schools-A-sermon-preach-d-at-St-Philip-s-church-in-Birmingham-August-9-1724-At-the-opening-of-a-charity-school-built-to-receive-an-hundred-children-by-Thomas-Bisse.pdf
    • http://loaminoo.linkpc.net/3092099097090092/A-Secure-Marriage-by-Diana-Hamilton.pdf