Malicious PDF — malware analysis report

Static analysis result for SHA-256 74d09e54641ad6d4…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 03:30:27 +01:00 Authoring application: mPDF 5.7
MD5: c75cf6e404db84138be3da6f31f52d2d SHA-1: b7e30868aa486250321905d00cf9477fd2d75ee9 SHA-256: 74d09e54641ad6d402c4f72e55e7070c887730e65da40cbe6fa157de2cd9dc91
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF was flagged by a critical heuristic for containing a mass external PDF link farm, with 24 numeric slug SEO PDF links identified. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely to lure users to potentially harmful content or phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099095095097099/The-Woman-Settler-s-Mine-3-by-Mechele-Armstrong.pdf
    • http://loaminoo.linkpc.net/3098098099099096/The-Wolf-Settler-s-Mine-4-by-Mechele-Armstrong.pdf
    • http://loaminoo.linkpc.net/3098091091098099/Currents-Blood-Lines-0-by-Mechele-Armstrong.pdf
    • http://loaminoo.linkpc.net/4099095097092099/Another-Dream-Another-Reality-Another-Dream-2-by-Mechele-Armstrong.pdf
    • http://loaminoo.linkpc.net/4099095097093096/Another-Night-Another-Dream-Another-Dream-1-by-Mechele-Armstrong.pdf
    • http://loaminoo.linkpc.net/7095092095094/Vengeance-Is-Mine-A-Novel-Of-Anne-Boleyn-Katherine-Howard-And-Lady-Rochford-The-Woman-Who-Helped-Destroy-Them-Both-by-Brandy-Purdy.pdf
    • http://loaminoo.linkpc.net/2096095098097090/Armstrong-Dent-and-the-Temple-of-Solomon-A-Classified-Armstrong-Dent-Thriller---Season-1-Book-7-by-Aeyess.pdf
    • http://loaminoo.linkpc.net/2096095097092098/Armstrong-Dent-and-the-Guerrilla-Revolucion-A-Classified-Armstrong-Dent-Tale---Season-1-Book-3-by-Aeyess.pdf
    • http://loaminoo.linkpc.net/1098090092096094/Mine-to-Spell-Mine-2-by-Janeal-Falor.pdf
    • http://loaminoo.linkpc.net/2091091092093096/Mine-to-Crave-Mine-4-by-Cynthia-Eden.pdf
    • http://loaminoo.linkpc.net/2091092095099093/Mine-to-Tarnish-Mine-0-5-by-Janeal-Falor.pdf
    • http://loaminoo.linkpc.net/2096093093091095/Mine-to-Hold-Mine-3-by-Cynthia-Eden.pdf
    • http://loaminoo.linkpc.net/2099098091092095/Mine-to-Lose-Mine-to-Love-1-by-T-K-Rapp.pdf
    • http://loaminoo.linkpc.net/2096095098094096/Armstrong-Dent-and-the-Death-of-the-Sun-A-Classified-Armstrong-Dent-Tale---Season-1-Book-2-by-Aeyess.pdf
    • http://loaminoo.linkpc.net/4095099091091093/Forever-You-re-Mine-MINE-4-by-K-Langston.pdf
    • http://loaminoo.linkpc.net/4099093090091094/Say-You-re-Mine-You-re-Mine-1-by-Jenika-Snow.pdf
    • http://loaminoo.linkpc.net/2099094093093094/Mine-All-Mine-by-Adam-Davies.pdf
    • http://loaminoo.linkpc.net/4099092097093096/You-Are-Mine-Mine-1-by-Janeal-Falor.pdf
    • http://loaminoo.linkpc.net/1099099090094094/She-s-All-Mine-Mine-1-by-Elena-Moreno.pdf
    • http://loaminoo.linkpc.net/3090099098097092/A-Friendship-s-Love-Settler-1-by-Melanie-Corona.pdf