Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca29efd44ecccb9c…

MALICIOUS

PDF

14.6 KB Created: 2019-05-02 21:08:40 +01:00 Authoring application: mPDF 5.7
MD5: ce0d88c4de1b974f9ffd5c9f82f70e30 SHA-1: 5f1986d2f3cb344696508622d00f8855f2dc837b SHA-256: ca29efd44ecccb9c4629d28e5bc880fd61fb14eb7cce5018883570872fb1302e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, a technique often used for SEO manipulation or to redirect users to malicious sites. While the specific URLs extracted were labeled as confirmed benign, the heuristic 'PDF_SEO_LINK_FARM' indicates a pattern of mass external linking. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099095099095098/Knights-of-Desire-Flights-of-Fancy-2-by-Melodee-Aaron.pdf
    • http://loaminoo.linkpc.net/8099096093096/Akiko-Flights-of-Fancy-by-Mark-Crilley.pdf
    • http://loaminoo.linkpc.net/8099097099092/Akiko-Flights-of-Fancy---The-High-Flying-Expanded-Edition-by-Mark-Crilley.pdf
    • http://loaminoo.linkpc.net/1097090090092094/Laced-with-Desire-Knights-of-the-Board-Room-3-by-Jaci-Burton.pdf
    • http://loaminoo.linkpc.net/1098094099096094/Fancy-Nancy-s-Favorite-Fancy-Words-From-Accessories-to-Zany-by-Jane-O-39-Connor.pdf
    • http://loaminoo.linkpc.net/6092094097091/Flight-of-Fancy-Cora-s-Daughters---The-Fancy-Series-by-Mercedes-Keyes.pdf
    • http://loaminoo.linkpc.net/2099095094096091/Bigfootloose-and-Finn-Fancy-Free-Finn-Fancy-Necromancy-2-by-Randy-Henderson.pdf
    • http://loaminoo.linkpc.net/1097095093098090/The-Blessed-Knights-Secret-Knights-2-by-Mary-Ting.pdf
    • http://loaminoo.linkpc.net/2099090094091098/Girls-Can-t-Be-Knights-Spirit-Knights-Book-1-by-Lee-French.pdf
    • http://loaminoo.linkpc.net/1091092092097095/Ethereal-Knights-Celestra-Knights-1-by-Addison-Moore.pdf
    • http://loaminoo.linkpc.net/3090090090091/The-Chosen-Knights-Secret-Knights-1-by-Mary-Ting.pdf
    • http://loaminoo.linkpc.net/4096098097094096/Silent-Knights-Knights-1-by-Gale-Stanley.pdf
    • http://loaminoo.linkpc.net/3090094090096093/Home-Run-The-Picture-Life-of-Henry-Aaron-by-Hank-Aaron.pdf
    • http://loaminoo.linkpc.net/8096095091/Flights-by-Olga-Tokarczuk.pdf
    • http://loaminoo.linkpc.net/1090099096096094090/Flights-of-Freedom-by-Ranga-Iyer.pdf
    • http://loaminoo.linkpc.net/3098096091099099/Submission-to-Desire-Desire-Oklahoma-7-by-Leah-Brooke.pdf
    • http://loaminoo.linkpc.net/2098092090094092/Creation-of-Desire-Desire-Oklahoma-3-by-Leah-Brooke.pdf
    • http://loaminoo.linkpc.net/4091091095099095/Blade-s-Desire-Desire-Oklahoma-2-by-Leah-Brooke.pdf
    • http://loaminoo.linkpc.net/2095091097092092/Rules-Of-Desire-Desire-Oklahoma-4-by-Leah-Brooke.pdf
    • http://loaminoo.linkpc.net/3095099098092099/Twisted-Knights-Angels-and-Demons-Twisted-Knights-MC-1-by-Lauren-Calhoun.pdf