Malicious PDF — malware analysis report

Static analysis result for SHA-256 8414f318f1d42c57…

MALICIOUS

PDF

16.9 KB Created: 2019-04-30 02:07:43 +01:00 Authoring application: mPDF 5.7
MD5: 0b03134bb7869e0202cebc3649394aec SHA-1: c653b5cb9b3dc866afd7d898af419b58af4adc57 SHA-256: 8414f318f1d42c57829f4d646c0d9141af891c5c4413892e2200d160709b4af2
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates this is a technique to generate traffic or potentially host malicious content. While the extracted URLs are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely to direct users to potentially harmful content or phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096094095090/Charlie-Bone-and-the-Castle-of-Mirrors-The-Children-of-the-Red-King-4-by-Jenny-Nimmo.pdf
    • http://loaminoo.linkpc.net/8098093095096/Midnight-for-Charlie-Bone-The-Children-of-the-Red-King-1-by-Jenny-Nimmo.pdf
    • http://loaminoo.linkpc.net/1091096094090098/Charlie-Bone-and-the-Beast-The-Children-of-the-Red-King-6-by-Jenny-Nimmo.pdf
    • http://loaminoo.linkpc.net/6093099098099/Charlie-Bone-and-the-Invisible-Boy-The-Children-of-the-Red-King-3-by-Jenny-Nimmo.pdf
    • http://loaminoo.linkpc.net/1091093098098090/Charlie-Bone-and-the-Hidden-King-The-Children-of-the-Red-King-5-by-Jenny-Nimmo.pdf
    • http://loaminoo.linkpc.net/4090094092096099/Ultramarine-by-Jenny-Nimmo.pdf
    • http://loaminoo.linkpc.net/1096094094094093/The-Owl-Tree-by-Jenny-Nimmo.pdf
    • http://loaminoo.linkpc.net/4092095097093091/Rainbow-and-Mr-Zed-Ultramarine-2-by-Jenny-Nimmo.pdf
    • http://loaminoo.linkpc.net/6096098095094095/The-Rinaldi-Ring-by-Jenny-Nimmo.pdf
    • http://loaminoo.linkpc.net/2097092096097092/Smoke-amp-Mirrors-THIRDS-7-by-Charlie-Cochet.pdf
    • http://loaminoo.linkpc.net/1092099091094095/Jenny-s-Castle-by-Elizabeth-Sinclair.pdf
    • http://loaminoo.linkpc.net/1099099099095093/Nobodaddy-s-Children-Scenes-from-the-Life-of-a-Faun-Brand-s-Heath-Dark-Mirrors-by-Arno-Schmidt.pdf
    • http://loaminoo.linkpc.net/1090094092091096091/Mirrors-A-Guide-To-The-Manufacture-Of-Mirrors-And-Reflecting-Surfaces-by-Bruno-Schweig.pdf
    • http://loaminoo.linkpc.net/3092091098091093/Children-of-Blood-and-Bone-Legacy-of-Or-sha-1-by-Tomi-Adeyemi.pdf
    • http://loaminoo.linkpc.net/7095096097/Children-of-Blood-and-Bone-Legacy-of-Or-sha-1-by-Tomi-Adeyemi.pdf
    • http://loaminoo.linkpc.net/7093098094098092/The-Lyons-Orphanage-by-Charlie-King.pdf
    • http://loaminoo.linkpc.net/3092095093097094/Screenplays-by-Stephen-King-Rose-Red-Kingdom-Hospital-Creepshow-the-Stand-Children-of-the-Corn-Cat-s-Eye-Pet-Sematary-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/2094095091090091/King-of-the-Castle-Queen-s-Rules-2-by-Treva-Harte.pdf
    • http://loaminoo.linkpc.net/1090097096093091090/Charlie-Muffin-s-Miracle-Mouse-by-Dick-King-Smith.pdf
    • http://loaminoo.linkpc.net/8092098099096090/The-Longed-Tales-The-Chained-King-and-the-Castle-of-Mystery-by-Mohamed-Abdulraheem.pdf