Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3d4bab3c4e3631d…

MALICIOUS

PDF

20.2 KB Created: 2019-04-30 04:53:37 +01:00 Authoring application: mPDF 5.7
MD5: b69e2887d1e846b7dacba57fc18b599c SHA-1: cf2beec6e0205d5d1d99608e4c31ea449c48b6bd SHA-256: b3d4bab3c4e3631d17e67a0b1fe10bd8b6ecab0d0f34560ee2b3d762b7ab621a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and contains a large number of embedded links to external resources, a technique often used for SEO manipulation or to distribute further malicious content. The primary heuristic indicates a link farm, suggesting the PDF's purpose is to redirect users to potentially harmful sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3098098099092098/Kate-s-Dilemma-Kate-s-Case-Files-3-by-Sarah-Holman.pdf
    • http://loaminoo.linkpc.net/2090096091095092/Case-Histories-A-Kate-Atkinson-CD-Box-Set-One-Good-Turn-Case-Histories-When-Will-There-Be-Good-News-by-Kate-Atkinson.pdf
    • http://loaminoo.linkpc.net/8094091093091/Works-by-Kate-Chopin-Novels-by-Kate-Chopin-Short-Stories-by-Kate-Chopin-Desiree-s-Baby-the-Awakening-the-Storm-the-Story-of-an-Hour-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/1091090098097095097/The-Heartreader-s-Secret-The-Faraday-Files-3-by-Kate-McIntyre.pdf
    • http://loaminoo.linkpc.net/1099095097093092/Case-Histories-by-Kate-Atkinson.pdf
    • http://loaminoo.linkpc.net/4093099091094090/The-Keepers-Files-1-5-A-Holding-Kate-Series-Book-by-LaDonna-Cole.pdf
    • http://loaminoo.linkpc.net/1096092097092092/Night-Shift-Kate-Daniels-6-5-SPI-Files-0-5-Psy-Changeling-12-5-Barbarian-1-by-Nalini-Singh.pdf
    • http://loaminoo.linkpc.net/2091092093097099/Pretty-When-She-Cries-by-Sarah-Kate.pdf
    • http://loaminoo.linkpc.net/4099095091097099/Doctor-Kate-Angel-on-Snowshoes-The-Story-of-Kate-Pelham-Newcomb-by-Adele-Comandini.pdf
    • http://loaminoo.linkpc.net/1091091097093091097/Kate-Kate-and-the-Bizzy-Girls-The-Queen-by-Deborah-Kanafani.pdf
    • http://loaminoo.linkpc.net/4092094096099/Blessed-Are-the-Cheesemakers-by-Sarah-Kate-Lynch.pdf
    • http://loaminoo.linkpc.net/4091092094099093/Waking-Kate-by-Sarah-Addison-Allen.pdf
    • http://loaminoo.linkpc.net/1090096094092090092/The-Case-of-the-Disappearing-Princess-The-New-Adventures-of-Mary-Kate-amp-Ashley-9-by-Lisa-Eisenberg.pdf
    • http://loaminoo.linkpc.net/1091091097093091096/Kate-kate-The-Fashion-Plate-by-Deborah-Kanafani.pdf
    • http://loaminoo.linkpc.net/1097093092096093/PBI-Case-Files-PBI-Case-Files-1-4-by-Jami-Brumfield.pdf
    • http://loaminoo.linkpc.net/4091098092090092/The-Case-of-the-Rock-Star-s-Secret-The-New-Adventures-of-Mary-Kate-amp-Ashley-16-by-Melinda-Metz.pdf
    • http://loaminoo.linkpc.net/1090096094092090093/The-Case-of-the-Rock-amp-Roll-Mystery-The-New-Adventures-of-Mary-Kate-amp-Ashley-6-by-Lisa-Eisenberg.pdf
    • http://loaminoo.linkpc.net/9090093091098090/Sarah-Morton-s-Day-A-Day-In-The-Life-Of-A-Pilgrim-Girl-by-Kate-Waters.pdf
    • http://loaminoo.linkpc.net/1099098094098099/Kissing-Kate-Amber-Kate-1-by-Via-Love.pdf
    • http://loaminoo.linkpc.net/2096096090098090/Heavenly-Hirani-s-School-of-Laughing-Yoga-by-Sarah-Kate-Lynch.pdf
    • http://loaminoo.linkpc.net/109609