Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9a4b9c9210525a0…

MALICIOUS

PDF

15.9 KB Created: 2019-05-02 01:28:45 +01:00 Authoring application: mPDF 5.7
MD5: 25460d4609757ef6fdcbd473d7681cc3 SHA-1: 3943871f14037a35f532b150544a13e85ec4445b SHA-256: a9a4b9c9210525a00b9468b197aa5f98136bfa1bd082e76d8960f44e66f7997f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While the specific content of the linked PDFs is benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to serve as a gateway to malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093092098099095/Hot-Trash-Trash-1-2-by-Cherie-Bennett.pdf
    • http://loaminoo.linkpc.net/2096096099093095/White-Trash-Love-Song-White-Trash-Trilogy-3-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/1094094097090098/White-Trash-Beautiful-White-Trash-Trilogy-1-by-Teresa-Mummert.pdf
    • http://loaminoo.linkpc.net/6090092090098097/With-Fate-Conspire-by-Yvonne-MacManus.pdf
    • http://loaminoo.linkpc.net/1097094090096092/How-the-White-Trash-Zombie-Got-Her-Groove-Back-White-Trash-Zombie-4-by-Diana-Rowland.pdf
    • http://loaminoo.linkpc.net/4093090091092092/The-Assassin-and-the-Pirate-Lord-Throne-of-Glass-0-1-by-Sarah-J-Maas.pdf
    • http://loaminoo.linkpc.net/1094094097094094/Ten-Ways-to-Be-Adored-When-Landing-a-Lord-Love-By-Numbers-2-by-Sarah-MacLean.pdf
    • http://loaminoo.linkpc.net/3093099095090090/White-Trash-Zombie-Unchained-White-Trash-Zombie-6-by-Diana-Rowland.pdf
    • http://loaminoo.linkpc.net/3096098092096098/Articles-on-Outlander-Including-Diana-Gabaldon-Lord-John-and-the-Private-Matter-Lord-John-and-the-Brotherhood-of-the-Blade-Lord-John-and-the-Scot-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/6096091092096093/Trash-by-Amy-Yamada.pdf
    • http://loaminoo.linkpc.net/3097099096098094/Submission-to-my-Lord-Lord-of-Discipline-Book-1-by-Alice-May-Ball.pdf
    • http://loaminoo.linkpc.net/6096091093092095/Trash-by-John-Knechtel.pdf
    • http://loaminoo.linkpc.net/2098096098090095/Trash-by-Dorothy-Allison.pdf
    • http://loaminoo.linkpc.net/5092098093099/Trash-by-Th-r-sa-Hedges.pdf
    • http://loaminoo.linkpc.net/2091090092097/The-Forbidden-Lord-Lord-Trilogy-2-by-Sabrina-Jeffries.pdf
    • http://loaminoo.linkpc.net/3097095095098096/Trash-Sex-Magic-by-Jennifer-Stevenson.pdf
    • http://loaminoo.linkpc.net/2098096092095097/Trailer-Trash-by-Marie-Sexton.pdf
    • http://loaminoo.linkpc.net/7097094092091093/Complete-Trash-by-Norm-Crampton.pdf
    • http://loaminoo.linkpc.net/1097094094091092/One-Man-s-Trash-Another-Man-s-Treasure-by-Yolanda-Allen.pdf
    • http://loaminoo.linkpc.net/2090099096091094/One-Man-s-Trash-Musicology-1-by-Yolanda-Allen.pdf
    • http://loaminoo.linkpc.net/3096098092096098/Articles-on-Outlander-Including-Diana-Gabaldon-Lord-John-and-the-Private-Matter-Lord-John-and-the-Brotherhood-of-the-Blade-Lord-John-and-the-Scot-by-Hephaestus-Bo