Malicious PDF — malware analysis report

Static analysis result for SHA-256 b4f4f64b2b0947ff…

MALICIOUS

PDF

18.8 KB Created: 2019-04-30 05:30:36 +01:00 Authoring application: mPDF 5.7
MD5: 3081937c0b8f05ff8777af3159de4040 SHA-1: a7179bd6d46d17e82207b2961a8be292a5d2229e SHA-256: b4f4f64b2b0947ff82e1b54cef64131b511ed36ab658f2ba98493be877df1ecb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, while individually marked as benign, collectively form a link farm, suggesting a potential attempt to drive traffic to malicious or compromised sites, possibly for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkp
    • http://loaminoo.linkpc.net/1090094094095099/An-Unexpected-Guest-by-Anne-Korkeakivi.pdf
    • http://loaminoo.linkpc.net/4095093096091097/The-Unexpected-Guest-by-Agatha-Christie.pdf
    • http://loaminoo.linkpc.net/1090090098094093091/Successful-Guest-Posting-How-to-Create-Guest-Posts-that-Drive-Traffic-and-Build-Authority-by-Tom-Ewer.pdf
    • http://loaminoo.linkpc.net/1090096094093093097/The-Jesse-Eisenberg-Handbook---Everything-You-Need-to-Know-about-Jesse-Eisenberg-by-Emily-Smith.pdf
    • http://loaminoo.linkpc.net/1090096094093098099/The-Jesse-Eisenberg-Handbook---Everything-You-Need-to-Know-about-Jesse-Eisenberg-by-Ricardo-Parrish.pdf
    • http://loaminoo.linkpc.net/1090096094092096096/The-Jesse-Eisenberg-Handbook---Everything-You-Need-to-Know-about-Jesse-Eisenberg-by-Victoria-Moses.pdf
    • http://loaminoo.linkpc.net/4090092095093097/The-Shackled-Continent-Africa-s-Past-Present-and-Future-Robert-Guest-by-Robert-Guest.pdf
    • http://loaminoo.linkpc.net/2097093095090092/An-Unexpected-Lesson-The-Unexpected-Book-1-by-Sophie-Walker.pdf
    • http://loaminoo.linkpc.net/7098099096093095/Unexpected-The-Complete-Collection-1-6-Unexpected-1-6-by-Amity-Cross.pdf
    • http://loaminoo.linkpc.net/1094091095097090/Uncle-Andy-s-A-Faabbbulous-Visit-With-Andy-Warhol-by-James-Warhola.pdf
    • http://loaminoo.linkpc.net/8091095097094/Dropping-in-with-Andy-Mac-The-Life-of-a-Pro-Skateboarder-by-Andy-MacDonald.pdf
    • http://loaminoo.linkpc.net/4092098090096092/Unexpected-Unexpected-1-by-Amity-Cross.pdf
    • http://loaminoo.linkpc.net/3094098099098095/The-Unexpected-Crush-Complete-Series-The-Unexpected-Crush-1-3-by-Alexa-Wilder.pdf
    • http://loaminoo.linkpc.net/1091095098098093099/Andy-Mc-Kee-Joyland-by-Andy-McKee.pdf
    • http://loaminoo.linkpc.net/3098099093091093/Andy-McBean-and-the-War-of-the-Worlds-The-Amazing-Adventures-of-Andy-McBean-1-by-Dale-Kutzera.pdf
    • http://loaminoo.linkpc.net/4096097095094097/Unexpected-Unexpected-1-by-Amy-Marie.pdf
    • http://loaminoo.linkpc.net/3094097094097090/The-Andy-Cohen-Diaries-A-Deep-Look-at-a-Shallow-Year-by-Andy-Cohen.pdf
    • http://loaminoo.linkpc.net/4095091092/Superficial-More-Adventures-from-The-Andy-Cohen-Diaries-by-Andy-Cohen.pdf
    • http://loaminoo.linkpc.net/1090096094093098095/In-God-s-Name-by-Sandy-Eisenberg-Sasso.pdf
    • http://loaminoo.linkpc.net/8090094090096098/Overnight-Sensation-by-Hal-Eisenberg.pdf