Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a616cc472c1cdb1…

MALICIOUS

PDF

21.4 KB Created: 2019-04-30 20:14:08 +01:00 Authoring application: mPDF 5.7
MD5: 2a0be73dfc885ffd1fea49a6596bc2ea SHA-1: 805140c388002f651a6cffe771dfa8aa0cf62558 SHA-256: 7a616cc472c1cdb1d529e31ce36233f8ca4530bbe869f6ba453b2dd8f9316d73
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these URLs are marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely related to SEO manipulation or directing users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4098095097099093/Karma-Gone-Bad-How-I-Learned-to-Love-Mangos-Bollywood-and-Water-Buffalo-by-Jenny-Feldon.pdf
    • http://loaminoo.linkpc.net/4093091095095095/Bollywood-and-the-Beast-Bollywood-Confidential-3-by-Suleikha-Snyder.pdf
    • http://loaminoo.linkpc.net/2095095099090/The-Bollywood-Bride-Bollywood-2-by-Sonali-Dev.pdf
    • http://loaminoo.linkpc.net/5094092091094090/Love-Karma-Use-Your-Intuition-to-Find-Create-and-Nurture-Love-in-Your-Life-by-Char-Margolis.pdf
    • http://loaminoo.linkpc.net/8094095094096091/Travels-and-Adventures-with-Clarissa-Pinkola-Estes-and-the-Buffalo-by-Buffalo-Kaplinski.pdf
    • http://loaminoo.linkpc.net/5093096090092091/Love-Lies-Karma-2-by-Kiera-Thomas.pdf
    • http://loaminoo.linkpc.net/4096098090096099/Love-s-a-Witch-Karma-s-Witches-2-by-Hope-Welsh.pdf
    • http://loaminoo.linkpc.net/3090091097099090/How-I-Learned-to-Love-the-Walrus-by-Beth-Orsoff.pdf
    • http://loaminoo.linkpc.net/2095090095090090/Chasing-Karma-Karma-1-by-C-Shell.pdf
    • http://loaminoo.linkpc.net/2095098097094095/It-s-Probably-Nothing-Or-How-I-Learned-to-Stop-Worrying-and-Love-My-Implants-by-Micki-Myers.pdf
    • http://loaminoo.linkpc.net/3095097096098095/How-I-Fell-in-Love-and-Learned-to-Shoot-Free-Throws-by-Jon-Ripslinger.pdf
    • http://loaminoo.linkpc.net/1093097091097094/Dr-Strangelove-or-How-I-Learned-to-Stop-Worrying-and-Love-the-Bomb-by-Peter-George.pdf
    • http://loaminoo.linkpc.net/2090090095091090/Married-with-Luggage-What-We-Learned-About-Love-by-Traveling-the-World-by-Warren-Talbot.pdf
    • http://loaminoo.linkpc.net/6098091099095098/Reeling-Through-Life-How-I-Learned-to-Live-Love-and-Die-at-the-Movies-by-Tara-Ison.pdf
    • http://loaminoo.linkpc.net/1091092093098090098/Trusting-God-to-Get-You-Through-How-to-Trust-God-Through-the-Fire--Lessons-I-ve-Learned-about-Grace-Loss-and-Love-by-Jason-Crabb.pdf
    • http://loaminoo.linkpc.net/1092093092097096/Homer-s-Odyssey-A-Fearless-Feline-Tale-or-How-I-Learned-about-Love-and-Life-with-a-Blind-Wonder-Cat-by-Gwen-Cooper.pdf
    • http://loaminoo.linkpc.net/3097093097094098/Confessions-of-a-Prairie-Bitch-How-I-Survived-Nellie-Oleson-and-Learned-to-Love-Being-Hated-by-Alison-Arngrim.pdf
    • http://loaminoo.linkpc.net/2094099096098095/Confessions-of-a-Prairie-Bitch-How-I-Survived-Nellie-Oleson-and-Learned-to-Love-Being-Hated-by-Alison-Arngrim.pdf
    • http://loaminoo.linkpc.net/1094097093099096/P-S-I-Still-Love-You-To-All-the-Boys-I-ve-Loved-Before-2-by-Jenny-Han.pdf
    • http://loaminoo.linkpc.net/6096090092099093/Love-s-Riff-by-Jenny-Siegel.pdf
    • http://loaminoo.linkpc.net/3090091097099090