Malicious PDF — malware analysis report

Static analysis result for SHA-256 8bbb9c447d7e6579…

MALICIOUS

PDF

18.3 KB Created: 2019-05-07 05:33:46 +01:00 Authoring application: mPDF 5.7
MD5: bd4b298e4af3f08106d0ba091cdbb190 SHA-1: 497e7bf04848c723b71620e2627cabef3b6f2770 SHA-256: 8bbb9c447d7e6579df837443dcb82e9e8dee4e849bbd1a9cb4a2aeb5b4167ef7
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by ClamAV as Pdf.Dropper.Agent-7380975-0 and a machine learning classifier. The primary heuristic indicates a PDF containing a mass external link farm, with numerous URLs pointing to book titles. The document body confirms the presence of these links, suggesting a potential SEO manipulation or a lure to download further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7380975-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7380975-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090099099094094091/Mick-Abruzzo-s-Story-Blackbird-Sisters-Mystery-0-5-by-Nancy-Martin.pdf
    • http://loaminoo.linkpc.net/2098095096094094/A-Little-Night-Murder-Blackbird-Sisters-Mystery-10-by-Nancy-Martin.pdf
    • http://loaminoo.linkpc.net/3095096090094097/Blackbird-Fly-Bennett-Sisters-1-by-Lise-McClendon.pdf
    • http://loaminoo.linkpc.net/1090099099094093095/Mick-Murphy-s-Law-A-Mick-Murphy-Key-West-Mystery-by-Michael-Haskins.pdf
    • http://loaminoo.linkpc.net/3094091092098092/Harlem-s-Little-Blackbird-The-Story-of-Florence-Mills-by-Ren-e-Watson.pdf
    • http://loaminoo.linkpc.net/7093099099098/Where-s-Nancy-Nancy-Drew-Girl-Detective-Super-Mystery-1-by-Carolyn-Keene.pdf
    • http://loaminoo.linkpc.net/4098093093092/The-Moonstone-Castle-Mystery-Nancy-Drew-Mystery-Stories-40-by-Carolyn-Keene.pdf
    • http://loaminoo.linkpc.net/1098090096095095/Mystery-at-the-Ski-Jump-Nancy-Drew-Mystery-Stories-29-by-Carolyn-Keene.pdf
    • http://loaminoo.linkpc.net/1090099099096096091/To-Beat-the-Devil-A-Mick-Murphy-Key-West-Mystery-by-Michael-Haskins.pdf
    • http://loaminoo.linkpc.net/4090095097091099/Sisters-One-Two-Three-by-Nancy-Star.pdf
    • http://loaminoo.linkpc.net/2095093090091093/Four-Queens-The-Proven-al-Sisters-Who-Ruled-Europe-by-Nancy-Goldstone.pdf
    • http://loaminoo.linkpc.net/4091090099098091/Sisters-of-the-Night-by-Martin-H-Greenberg.pdf
    • http://loaminoo.linkpc.net/1091092090098092091/As-Equals-And-As-Sisters-Feminism-The-Labor-Movement-And-The-Women-s-Trade-Union-League-Of-New-York-by-Nancy-Schrom-Dye.pdf
    • http://loaminoo.linkpc.net/2097094094097094/The-Sisters-of-Sinai-How-Two-Lady-Adventurers-Discovered-the-Hidden-Gospels-by-Janet-Martin-Soskice.pdf
    • http://loaminoo.linkpc.net/2092091098091091/Murder-on-Sisters-Row-Gaslight-Mystery-13-by-Victoria-Thompson.pdf
    • http://loaminoo.linkpc.net/2091090094091097/Dearly-Departed-Secret-Sisters-Mystery-2-by-Tristi-Pinkston.pdf
    • http://loaminoo.linkpc.net/3094095094096098/Dear-Mystery-Guy-Magnolia-Sisters-Book-1-by-Brenda-Barrett.pdf
    • http://loaminoo.linkpc.net/4099091098097096/Spell-Found-Blackmore-Sisters-Mystery-7-by-Leighann-Dobbs.pdf
    • http://loaminoo.linkpc.net/7099096091/Daughters-of-the-Winter-Queen-Four-Remarkable-Sisters-the-Crown-of-Bohemia-and-the-Enduring-Legacy-of-Mary-Queen-of-Scots-by-Nancy-Goldstone.pdf
    • http://loaminoo.linkpc.net/3098091097096099/Peril-By-Ponytail-Bad-Hair-Day-Mystery-12-by-Nancy-J-Cohen.pdf
    • http://loaminoo.linkpc.net/2095093090091093/Four-Queens-The-Proven-al-Sisters-Who-Ru