Malicious PDF — malware analysis report

Static analysis result for SHA-256 bfb425a50e46f116…

MALICIOUS

PDF

13.4 KB Created: 2019-04-29 23:15:01 +01:00 Authoring application: mPDF 5.7
MD5: cfa283d97145e0eb43f33e721ff9dd5e SHA-1: 090f6b5578de7030fa4121b60b6b8bac3f4c586d SHA-256: bfb425a50e46f116055c83dbe3c268dba6d358ccc57132df544ef20e528c6ead
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, constituting a link farm. The heuristic PDF_SEO_LINK_FARM indicates that these URLs are likely designed to direct users to external content, potentially as a lure. While the document body is heavily obfuscated, the presence of numerous links to book-related PDFs suggests a social engineering tactic to drive traffic to potentially malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/1094095094093098/Everything-Will-Be-All-Right-by-Tessa-Hadley.pdf
    • http://loaminoo.linkpc.net/1097090093/The-Past-by-Tessa-Hadley.pdf
    • http://loaminoo.linkpc.net/3095093098090094/Married-Love-by-Tessa-Hadley.pdf
    • http://loaminoo.linkpc.net/5091092097092098/Sunstroke-and-Other-Stories-by-Tessa-Hadley.pdf
    • http://loaminoo.linkpc.net/3096096098095090/Married-Love-and-Other-Stories-by-Tessa-Hadley.pdf
    • http://loaminoo.linkpc.net/2095092096097098/211-Things-a-Clever-Girl-Can-Do-by-Bunty-Cutler.pdf
    • http://loaminoo.linkpc.net/3091099092099094/Caterina-the-Clever-Farm-Girl-by-Julienne-Peterson.pdf
    • http://loaminoo.linkpc.net/4099097094092/Clever-Girl-Elizabeth-Bentley-the-Spy-Who-Ushered-in-the-McCarthy-Era-by-Lauren-Kessler.pdf
    • http://loaminoo.linkpc.net/3096090092098097/Hadley-The-Club-Girl-Diaries-3-by-Addison-Jane.pdf
    • http://loaminoo.linkpc.net/4090090095095099/Tessa-s-Dilemma-by-Tessa-Wanton.pdf
    • http://loaminoo.linkpc.net/7092095096098099/Clever-Noo-Noo-by-BBC.pdf
    • http://loaminoo.linkpc.net/3098090097097090/Mr-Clever-Mr-Men-37-by-Roger-Hargreaves.pdf
    • http://loaminoo.linkpc.net/3092090099095097/Stolen-Girl-A-Good-Girl-s-Guide-to-Getting-Kidnapped-and-Girl-On-Fire-by-Yxta-Maya-Murray.pdf
    • http://loaminoo.linkpc.net/1091093092098095091/Clever-Gretchen-by-John-Warren-Stewig.pdf
    • http://loaminoo.linkpc.net/3091091093097092/Too-Clever-IX-Darell-and-Bobo-by-Julia-E-Antoine.pdf
    • http://loaminoo.linkpc.net/1090092099092096/Clever-Leading-Your-Smartest-Most-Creative-People-by-Rob-Goffee.pdf
    • http://loaminoo.linkpc.net/4095094094098098/Dead-Clever-Lily-Pascale-1-by-Scarlett-Thomas.pdf
    • http://loaminoo.linkpc.net/6091094092096092/12-Prom-Asking-Ideas-For-A-Promposal-Too-Clever-To-Turn-Down-by-Mrs-Rosee.pdf
    • http://loaminoo.linkpc.net/4090091092091097/Clever-Jack-Takes-the-Cake-by-Candace-Fleming.pdf
    • http://loaminoo.linkpc.net/2096094094099090/The-Clever-Woman-of-the-Family-by-Charlotte-Mary-Yonge.pdf