Malicious PDF — malware analysis report

Static analysis result for SHA-256 91046c5417ef2e9c…

MALICIOUS

PDF

18.0 KB Created: 2019-05-02 05:18:52 +01:00 Authoring application: mPDF 5.7
MD5: 18ba46f02c167c6212540cfdea81d646 SHA-1: c94ee27677032fae914bf633b46633c29f8aa06a SHA-256: 91046c5417ef2e9c61e8497f606950c6e29c1ada2a108902b9bc86f03e0b85f6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged this file with high confidence. The embedded links point to various book titles, suggesting a lure to disguise malicious intent. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098092090092091/The-Pursuit-of-Mary-Bennet-A-Pride-amp-Prejudice-Novel-by-Pamela-Mingle.pdf
    • http://loaminoo.linkpc.net/2098092091096093/Kitty-Bennet-s-Diary-Pride-amp-Prejudice-Chronicles-3-by-Anna-Elliott.pdf
    • http://loaminoo.linkpc.net/2098091099098096/Alias-Thomas-Bennet-A-Pride-and-Prejudice-Variation-by-Suzan-Lauder.pdf
    • http://loaminoo.linkpc.net/2098091098097096/Georgiana-Darcy-s-Diary-Jane-Austen-s-Pride-and-Prejudice-Continued-Pride-and-Prejudice-Chronicles-1-by-Anna-Elliott.pdf
    • http://loaminoo.linkpc.net/2098092093099097/Pride-and-Prejudice-and-Poison-A-Pride-and-Prejudice-Novel-Variation-by-Bella-Breen.pdf
    • http://loaminoo.linkpc.net/2098092094090095/Becoming-Mary-A-Pride-and-Prejudice-Sequel-by-Amy-Street.pdf
    • http://loaminoo.linkpc.net/3099090090095095/A-Very-Mary-Christmas-A-Pride-and-Prejudice-Novella-by-Leenie-Brown.pdf
    • http://loaminoo.linkpc.net/2098092094093090/When-Mary-Met-the-Colonel-A-Pride-and-Prejudice-Novella-by-Victoria-Kincaid.pdf
    • http://loaminoo.linkpc.net/2098091098097097/Darcy-on-the-Hudson-A-Pride-and-Prejudice-Re-imagining-by-Mary-Lydon-Simonsen.pdf
    • http://loaminoo.linkpc.net/9097094098094096/Pride-and-Prejudice-and-Zombies-Pride-and-Prejudice-and-Zombies-Dawn-of-the-Dreadfuls-by-Seth-Grahame-Smith.pdf
    • http://loaminoo.linkpc.net/6097093092096091/PRIDE-AND-PREJUDICE-Jane-Austen-author-of-Mansfield-Park-Persuasion-Sense-and-Sensibility-Northanger-Pride-and-Prejudice-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1098098091090090/Pride-Prejudice-and-Cheese-Grits-Jane-Austen-Takes-the-South-1-by-Mary-Jane-Hathaway.pdf
    • http://loaminoo.linkpc.net/4092092090094097/Pride-Prejudice-and-Cheese-Grits-Jane-Austen-Takes-the-South-1-by-Mary-Jane-Hathaway.pdf
    • http://loaminoo.linkpc.net/3092094095090097/Pride-Prejudice-and-Cheese-Grits-Jane-Austen-Takes-the-South-1-by-Mary-Jane-Hathaway.pdf
    • http://loaminoo.linkpc.net/1096096093090092/Pride-Prejudice-and-Cheese-Grits-Jane-Austen-Takes-the-South-1-by-Mary-Jane-Hathaway.pdf
    • http://loaminoo.linkpc.net/5095094094090094/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/9095094099094093/Pride-amp-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/5097098093099091/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/9094096/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/7094096094098092/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/2098091098097097/Darcy-on-the-Hudson-A-Pride-and-Prejudice-Re-imagining-b