Malicious PDF — malware analysis report

Static analysis result for SHA-256 736b4346680fc663…

MALICIOUS

PDF

19.4 KB Created: 2019-05-07 04:16:27 +01:00 Authoring application: mPDF 5.7
MD5: 4de64ecc2784d2964721ea34a5a3988b SHA-1: c5fb0720276039e258c390ddc9de42399cb9fbd2 SHA-256: 736b4346680fc66347f30c05dfcb466c2e6da0a7a8c221cd9b4c4607b70615ae
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a heuristic firing for a 'PDF_SEO_LINK_FARM', indicating a large number of embedded external links. While most linked URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a potential attempt to manipulate search engine results or to distribute further malicious content. The ML classifier also flagged the document as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090094099090097/The-Little-Mermaid-Ursula-My-Side-of-the-Story-3-by-Daphne-Skinner.pdf
    • http://loaminoo.linkpc.net/8096092091091096/Saint-Ursula-Story-of-Ursula-and-Dream-of-Ursula-by-John-Ruskin.pdf
    • http://loaminoo.linkpc.net/1091096092096096091/Skinner-s-Round-Bob-Skinner-4-by-Quintin-Jardine.pdf
    • http://loaminoo.linkpc.net/1091096092096095099/Skinner-s-Trail-Bob-Skinner-3-by-Quintin-Jardine.pdf
    • http://loaminoo.linkpc.net/1091096092097090099/Skinner-s-Ghosts-Bob-Skinner-7-by-Quintin-Jardine.pdf
    • http://loaminoo.linkpc.net/1091096092097091093/Skinner-s-Ordeal-Bob-Skinner-5-by-Quintin-Jardine.pdf
    • http://loaminoo.linkpc.net/3090092099094097/The-Mermaid-Girl-A-Story-by-Erika-Swyler.pdf
    • http://loaminoo.linkpc.net/3098094091093091/The-Mermaid-Girl-A-Story-by-Erika-Swyler.pdf
    • http://loaminoo.linkpc.net/1090093097091098092/The-Mermaid-Catches-Her-Mate-A-Nocturne-Falls-Universe-story-by-Jax-Cassidy.pdf
    • http://loaminoo.linkpc.net/2090094099096092/No-Kidding-Mermaids-Are-a-Joke-The-Story-of-the-Little-Mermaid-as-Told-by-the-Prince-by-Nancy-Loewen.pdf
    • http://loaminoo.linkpc.net/1091090095096091/Mermaid-Queen-The-Spectacular-True-Story-Of-Annette-Kellerman-Who-Swam-Her-Way-To-Fame-Fortune-Swimsuit-History-by-Shana-Corey.pdf
    • http://loaminoo.linkpc.net/4092098094094099/My-Side-of-the-Story-by-Will-Davis.pdf
    • http://loaminoo.linkpc.net/7093091093092091/The-Daphne-du-Maurier-Companion-Rebecca-My-Cousin-Rachel-Frenchman-s-Creek-by-Daphne-du-Maurier.pdf
    • http://loaminoo.linkpc.net/7093091091091098/Murder-on-the-Cliffs-A-Daphne-du-Maurier-Mystery-Daphne-du-Maurier-Mysteries-1-by-Joanna-Challis.pdf
    • http://loaminoo.linkpc.net/7093091091097094/Daphne-du-Maurier-Collection-Rebecca-Frenchman-s-Creek-Jamaica-Inn-by-Daphne-du-Maurier.pdf
    • http://loaminoo.linkpc.net/1096099090094092/The-Other-Side-of-the-Mountain-The-Story-of-Jill-Kinmont-by-E-G-Valens.pdf
    • http://loaminoo.linkpc.net/4095097090096095/Romeo-and-Juliet-and-West-Side-Story-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/1090093094090097090/Romeo-and-Juliet-West-Side-Story-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/1096092090096/This-Hallowed-Ground-The-Story-of-the-Union-Side-of-the-Civil-War-by-Bruce-Catton.pdf
    • http://loaminoo.linkpc.net/2095096092094094/The-Other-Side-of-the-River-A-Story-of-Two-Towns-a-Death-and-America-s-Dilemma-by-Alex-Kotlowitz.pdf