Malicious PDF — malware analysis report

Static analysis result for SHA-256 aae0d5229d9b7f4a…

MALICIOUS

PDF

13.3 KB Created: 2019-05-03 05:58:42 +01:00 Authoring application: mPDF 5.7
MD5: e47d2cbc3c1fcf476c6708ded0d442e4 SHA-1: 62f063c65f1a5334613aae7d056e268e5e7cd59b SHA-256: aae0d5229d9b7f4a2799b9741f72a1943b8f1d6633c6553d974abfd3c50e8ece
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links to external PDFs. The heuristic 'PDF_SEO_LINK_FARM' indicates that these links are likely part of a strategy to manipulate search engine results or drive traffic to malicious sites. The primary attack pattern involves leveraging these links, potentially as a lure or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9839

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099098093096097/Willing-Surrender-Willing-Surrender-1-by-Carrie-Hogle.pdf
    • http://loaminoo.linkpc.net/2096091095095097/Surrender-the-Pink-by-Carrie-Fisher.pdf
    • http://loaminoo.linkpc.net/4092094097098096/Surrender-Surrender-1-by-Melody-Anne.pdf
    • http://loaminoo.linkpc.net/1090093093094/Surrender-Your-Love-Surrender-Your-Love-1-by-J-C-Reed.pdf
    • http://loaminoo.linkpc.net/1094099092096097/For-Us-Surrender-is-Out-of-the-Question-by-Mac-McClelland.pdf
    • http://loaminoo.linkpc.net/1096090096098092/Unconditional-Surrender-by-Cat-Grant.pdf
    • http://loaminoo.linkpc.net/1097090096090098/Mountain-Surrender-by-Mae-Shields.pdf
    • http://loaminoo.linkpc.net/1091091091099099093/I-Surrender-All-by-Clay-Crosse.pdf
    • http://loaminoo.linkpc.net/4097092096097096/Cairo-Surrender-by-Habu.pdf
    • http://loaminoo.linkpc.net/2094094099095093/Terms-of-Surrender-by-Wheldrake.pdf
    • http://loaminoo.linkpc.net/4099099092094/Surrender-by-Sonya-Hartnett.pdf
    • http://loaminoo.linkpc.net/4096090093091097/The-Lover-s-Surrender-No-Exceptions-4-by-J-C-Reed.pdf
    • http://loaminoo.linkpc.net/3094097096093093/Texas-Surrender-by-Claire-Thompson.pdf
    • http://loaminoo.linkpc.net/1094098099090096/Lycan-s-Surrender-by-Jaci-Burton.pdf
    • http://loaminoo.linkpc.net/1097093096095093/Submit-Surrender-2-by-Melody-Anne.pdf
    • http://loaminoo.linkpc.net/1092092095095095/Surrender-Harris-Brothers-4-by-Amy-Daws.pdf
    • http://loaminoo.linkpc.net/1090098095094097/Ultimate-Surrender-by-Jill-Shalvis.pdf
    • http://loaminoo.linkpc.net/5098091097096/Surrender-of-the-Heart-by-Sally-D-John.pdf
    • http://loaminoo.linkpc.net/2094096090093094/Surrender-A-Dream-by-Jill-Barnett.pdf
    • http://loaminoo.linkpc.net/2094096091092094/Seduced-Surrender-3-by-Melody-Anne.pdf
    • http://loaminoo.linkpc.net/1094098099090096/Lycan-s-Surrender-by-Jac