Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f04a7149fd387e3…

MALICIOUS

PDF

20.3 KB Created: 2019-05-01 18:51:19 +01:00 Authoring application: mPDF 5.7
MD5: 0b4796ee8d11546cd74282239792d5e8 SHA-1: 228ece05f0d477fa6c08a61c2482edf5478d6604 SHA-256: 7f04a7149fd387e3cf096a8549c947399802ffbdf6ca9eca223168900762b371
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged the document as malicious. These indicators suggest the document is designed to redirect users to potentially harmful or unwanted content, rather than serving a legitimate purpose. The primary technique observed is the use of embedded links to external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7096094091096097/Beautiful-MILF-bodies-Sexy-photobook-of-stunning-boobs-and-asses-11-Hot-mothers-have-never-been-so-horny-by-Kito-Mori.pdf
    • http://loaminoo.linkpc.net/7096094091095093/Beautiful-MILF-bodies-Sexy-photobook-of-stunning-boobs-and-asses-13-Hot-mothers-have-never-been-so-horny-by-Kito-Mori.pdf
    • http://loaminoo.linkpc.net/7096094090093099/Beautiful-MILF-bodies-Sexy-photobook-of-stunning-boobs-and-asses-7-Hot-mothers-have-never-been-so-horny-by-Kito-Mori.pdf
    • http://loaminoo.linkpc.net/7096094091095097/Beautiful-MILF-bodies-Sexy-photobook-of-stunning-boobs-and-asses-10-Hot-mothers-have-never-been-so-horny-by-Kito-Mori.pdf
    • http://loaminoo.linkpc.net/7096094090093094/Beautiful-MILF-bodies-Sexy-photobook-of-stunning-boobs-and-asses-3-Hot-mothers-have-never-been-so-horny-by-Kito-Mori.pdf
    • http://loaminoo.linkpc.net/7096094091095095/Beautiful-MILF-bodies-Sexy-photobook-of-stunning-boobs-and-asses-16-by-Kito-Mori.pdf
    • http://loaminoo.linkpc.net/7092091099096099/Sexy-Boobs-and-Butts-by-Benny-Dormann.pdf
    • http://loaminoo.linkpc.net/3093092091091092/Sexy-Bodies-by-Elizabeth-Grosz.pdf
    • http://loaminoo.linkpc.net/2090091093097096/The-Mad-And-Beautiful-Mothers-by-Patricia-Young.pdf
    • http://loaminoo.linkpc.net/8090099092099090/Beautiful-Bodies-A-Novel-by-Laura-Shaine-Cunningham.pdf
    • http://loaminoo.linkpc.net/8095092091098092/MILF-PICS-23-SEX-MILF-by-Teddy-Bannis.pdf
    • http://loaminoo.linkpc.net/6098099096097091/Reframing-the-Practice-of-Philosophy-Bodies-of-Color-Bodies-of-Knowledge-by-George-Yancy.pdf
    • http://loaminoo.linkpc.net/1090095094095090096/Despotic-Bodies-and-Transgressive-Bodies-Spanish-Culture-from-Francisco-Franco-to-Jesus-Franco-by-Tatjana-Pavlovi-.pdf
    • http://loaminoo.linkpc.net/7095097094090094/The-Historical-Fiction-of-Mori-Ogai-by-gai-Mori.pdf
    • http://loaminoo.linkpc.net/1097094090/Lock-amp-Mori-Lock-amp-Mori-1-by-Heather-W-Petty.pdf
    • http://loaminoo.linkpc.net/3090098099098092/The-Sexy-amp-The-Undead-Sexy-Witches-1-by-Charity-Parkerson.pdf
    • http://loaminoo.linkpc.net/4093093095091091/The-Sexy-Professor-Redemption-The-Sexy-Series-by-T-R-Bertrand.pdf
    • http://loaminoo.linkpc.net/4093093099097095/The-Sexy-Boss-Sedition-The-Sexy-Series-by-T-R-Bertrand.pdf
    • http://loaminoo.linkpc.net/6090094099097096/Sexy-Hart-Sexy-3-by-Dani-Lovell.pdf
    • http://loaminoo.linkpc.net/2096094090093090/Sexy-Summers-Sexy-2-by-Dani-Lovell.pdf