Malicious PDF — malware analysis report

Static analysis result for SHA-256 bfb49215109815c9…

MALICIOUS

PDF

15.5 KB Created: 2019-05-02 00:50:23 +01:00 Authoring application: mPDF 5.7
MD5: dde1b069031b9d5a41761eb10d9dc6b0 SHA-1: d9fdbf91ef4a17e56b56ca8ff7daa6ff71bd2455 SHA-256: bfb49215109815c9eb9ff83397567abe0d2d403e18ef00690bd4ca85f70b3ae2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO manipulation tactic. While the URLs themselves are currently marked as benign, the sheer volume and the ML classifier's high confidence indicate a malicious intent, likely to direct users to malicious sites or to manipulate search engine rankings. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097097090099096/The-Guardian-Duke-Forgotten-Castles-1-by-Jamie-Carie.pdf
    • http://loaminoo.linkpc.net/7099097094098/Angel-s-Den-by-Jamie-Carie.pdf
    • http://loaminoo.linkpc.net/3097093096096095/A-Highlander-For-Christmas-by-Jamie-Carie.pdf
    • http://loaminoo.linkpc.net/2097092097092097/A-Highlander-for-Christmas-by-Jamie-Carie.pdf
    • http://loaminoo.linkpc.net/2093094097091097/Pirate-of-My-Heart-by-Jamie-Carie.pdf
    • http://loaminoo.linkpc.net/3092090092095094/Rush-to-the-Altar-by-Jamie-Carie.pdf
    • http://loaminoo.linkpc.net/3091096099092098/Romancing-the-Duke-Castles-Ever-After-1-by-Tessa-Dare.pdf
    • http://loaminoo.linkpc.net/1090091097094/Romancing-the-Duke-Castles-Ever-After-1-by-Tessa-Dare.pdf
    • http://loaminoo.linkpc.net/3091094098090092/Castles-on-the-Sand-Shattered-Castles-1-by-E-M-Tippetts.pdf
    • http://loaminoo.linkpc.net/3099099090097091/Forgotten-amp-Remembered-The-Duke-s-Late-Wife-Love-s-Second-Chance-1-by-Bree-Wolf.pdf
    • http://loaminoo.linkpc.net/8091092095098092/Castles-of-Britain-and-Ireland-The-Ultimate-Reference-Book-A-Region-By-Region-Guide-to-over-1-350-Castles-by-Peter-Somerset-Fry.pdf
    • http://loaminoo.linkpc.net/4093095098096099/The-Fallen-Guardian-The-Guardian-Chronicles-2-by-Steven-R-Burke.pdf
    • http://loaminoo.linkpc.net/2097097091098097/The-Last-Mage-Guardian-Guardian-s-Compact-1-by-Sabrina-Chase.pdf
    • http://loaminoo.linkpc.net/4090098091091092/The-Duke-s-Indiscretion-Duke-Trilogy-3-by-Adele-Ashworth.pdf
    • http://loaminoo.linkpc.net/3091096099099091/The-Duke-amp-The-Vicar-s-Daughter-Duke-10-by-Fenella-J-Miller.pdf
    • http://loaminoo.linkpc.net/2094095099090094/For-Love-of-the-Duke-The-Heart-of-a-Duke-1-by-Christi-Caldwell.pdf
    • http://loaminoo.linkpc.net/3094099090094090/Heir-to-the-Duke-The-Duke-s-Sons-1-by-Jane-Ashford.pdf
    • http://loaminoo.linkpc.net/3094099094094093/What-the-Duke-Doesn-t-Know-The-Duke-s-Sons-2-by-Jane-Ashford.pdf
    • http://loaminoo.linkpc.net/2096098095093094/The-Guardian-s-Keeper-The-Guardian-Trilogy-1-by-T-R-Raven.pdf
    • http://loaminoo.linkpc.net/3096090091093098/The-Guardian-The-Guardian-Interviews-1-by-Michael-Clary.pdf
    • http://loaminoo.linkpc.net/8091092095098092/Castles-of-Britain-and-Ireland-The-Ultimate-Reference-Book-A-Region-By-Region-Guide-to-over-1-350-Castles-by-