Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1c742ab02ef4359…

MALICIOUS

PDF

14.1 KB Created: 2019-04-30 04:59:34 +01:00 Authoring application: mPDF 5.7
MD5: c42ef38ca0a4de338c4c96f35f7d8383 SHA-1: ce47276134e3b28d337f54b5f70f094ef9938253 SHA-256: b1c742ab02ef4359d0212096bd19d0bc26004f5f2773a876264a47c8e5813830
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified as a link farm, directing users to external book-related URLs. The ML classifier strongly indicated maliciousness, and the heuristic confirms the presence of a link farm. The primary attack pattern involves tricking users into visiting these external sites, which could host further malicious content or phishing attempts.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3093093097098098/Into-the-Looking-Glass-Looking-Glass-1-by-John-Ringo.pdf
    • http://loaminoo.linkpc.net/6097095099094/Girl-Under-Glass-Glass-and-Iron-1-by-Monica-Enderle-Pierce.pdf
    • http://loaminoo.linkpc.net/4094093098094094/Shards-of-Glass-The-Glass-Trilogy-1-by-Arianne-Richmonde.pdf
    • http://loaminoo.linkpc.net/1099096092099097/Through-Glass-Episode-One-Through-Glass-1-by-Rebecca-Ethington.pdf
    • http://loaminoo.linkpc.net/2091093095099096/Sea-Glass-Glass-2-by-Maria-V-Snyder.pdf
    • http://loaminoo.linkpc.net/3095096090094/Spy-Glass-Glass-3-by-Maria-V-Snyder.pdf
    • http://loaminoo.linkpc.net/3095090090098096/The-Looking-Glass-War-by-John-le-Carr-.pdf
    • http://loaminoo.linkpc.net/4095094099091098/Sisters-of-Glass-by-D-W-St-John.pdf
    • http://loaminoo.linkpc.net/2094090093098095/The-Spy-Who-Came-In-From-The-Cold-The-Looking-Glass-War-by-John-le-Carr-.pdf
    • http://loaminoo.linkpc.net/3092099093090097/Nyssa-Glass-and-the-Juliet-Dilemma-Nyssa-Glass-2-by-H-L-Burke.pdf
    • http://loaminoo.linkpc.net/3099098090093097/Ghosts-of-Glass-by-Christopher-St-John-Sampayo.pdf
    • http://loaminoo.linkpc.net/1097096096091097/Raise-Your-Glass-Tales-from-Foster-High-3-by-John-Goode.pdf
    • http://loaminoo.linkpc.net/6095099097/The-Glass-Spare-The-Glass-Spare-1-by-Lauren-DeStefano.pdf
    • http://loaminoo.linkpc.net/7091098094095/Throne-of-Glass-Throne-of-Glass-1-by-Sarah-J-Maas.pdf
    • http://loaminoo.linkpc.net/3094091097091/Throne-of-Glass-Throne-of-Glass-1-by-Sarah-J-Maas.pdf
    • http://loaminoo.linkpc.net/2098091097/Burning-Glass-Burning-Glass-1-by-Kathryn-Purdie.pdf
    • http://loaminoo.linkpc.net/4099093094094092/Throne-of-Glass-Throne-of-Glass-1-by-Sarah-J-Maas.pdf
    • http://loaminoo.linkpc.net/3092091090092094/Throne-of-Glass-Throne-of-Glass-1-by-Sarah-J-Maas.pdf
    • http://loaminoo.linkpc.net/8096096094092/The-Green-Glass-Sea-Green-Glass-1-by-Ellen-Klages.pdf
    • http://loaminoo.linkpc.net/3094093090095/The-Looking-Glass-Wars-The-Looking-Glass-Wars-1-by-Frank-Beddor.pdf