Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d31216f57c21c0e…

MALICIOUS

PDF

14.5 KB Created: 2019-04-30 05:49:08 +01:00 Authoring application: mPDF 5.7
MD5: 16d28b4242630aafe7e0ba4a4b835dcf SHA-1: dd3be8b5ac75f7f265297d25273bb3d63c2fc0ca SHA-256: 9d31216f57c21c0e0ca0f7bd406ed49a8bf14e24da6825744aa522d0bb604f01
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the document body is heavily corrupted, the presence of numerous links suggests a malicious intent, possibly to direct users to phishing sites or to distribute further malware. The primary IOCs are the URLs embedded within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097094093094099/Breaking-Sin-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/3095096091096097/Rellik-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/1097094091091097/Depravity-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/1096097090096099/Safe-Word-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/2099093098098092/Kat-s-Tale-Undying-Love-1-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/1097098094092094/9-Lives-Undying-Love-2-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/7096095092095096/Honor-and-Obey-Honor-3-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/7097094090092/Honor-Student-Honor-1-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/5094096091/Where-Good-Girls-Go-To-Die-Good-Girls-1-by-Holly-Renee.pdf
    • http://loaminoo.linkpc.net/2096096099093095/White-Trash-Love-Song-White-Trash-Trilogy-3-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/7098091094095093/Bad-Girls-Why-Men-Love-Them-amp-How-Good-Girls-Can-Learn-Their-Secrets-by-Carole-Lieberman.pdf
    • http://loaminoo.linkpc.net/1094094097090098/White-Trash-Beautiful-White-Trash-Trilogy-1-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/4099099092094095/Educate-Girls-Around-The-World-Good-People-Doing-Good-Work-by-Shay-Spivey.pdf
    • http://loaminoo.linkpc.net/3095094095097092/Where-Bad-Girls-Go-to-Fall-Good-Girls-2-by-Holly-Renee.pdf
    • http://loaminoo.linkpc.net/2092096094090094/Undying-Love-Undying-Love-1-3-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/2093095091094099/Martha-Martha-The-Good-Part-by-Teresa-R-Jones.pdf
    • http://loaminoo.linkpc.net/2094091098098090/Catching-Liam-Good-Girls-Don-t-1-by-Geneva-Lee.pdf
    • http://loaminoo.linkpc.net/2098098095093099/Katie-bug-Good-Girls-2-by-Joan-Defers.pdf
    • http://loaminoo.linkpc.net/3097094092098094/Marked-Down-for-Murder-Good-Buy-Girls-4-by-Josie-Belle.pdf
    • http://loaminoo.linkpc.net/5096096099099090/Moneymakers-Good-Cents-for-Girls-by-Ingrid-Roper.pdf
    • http://loaminoo.linkpc.net/1094094097090098/White-Trash-Beautiful-White-Trash-T