Malicious PDF — malware analysis report

Static analysis result for SHA-256 cafcc1ab3cddb82c…

MALICIOUS

PDF

14.0 KB Created: 2019-04-30 03:33:24 +01:00 Authoring application: mPDF 5.7
MD5: 9e3f03627e8e22592c2e64bd19d7375e SHA-1: da32d996946fed83dcdd09d9886d98460a541f85 SHA-256: cafcc1ab3cddb82ce270eb46ff05c80875f6e906b18cc7706e451a82457bfb04
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. While the specific URLs extracted were labeled as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to redirect users to malicious content. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6097097099098/Caged-Wolf-Wolves-of-Willow-Bend-2-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/1098098092092096/Wolf-At-Law-Wolves-of-Willow-Bend-0-5-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/2095090093092093/Bayou-Wolf-Wolves-of-Willow-Bend-5-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/3098093090097097/Untamed-Wolf-Wolves-of-Willow-Bend-6-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/4095092099097096/Willow-Bend-by-Ally-Blue.pdf
    • http://loaminoo.linkpc.net/4098094092092097/Caged-Wolf-The-Tarot-Witches-1-by-S-M-Reine.pdf
    • http://loaminoo.linkpc.net/4091091090094099/Caged-Wolf-The-Tarot-Witches-1-by-S-M-Reine.pdf
    • http://loaminoo.linkpc.net/1091095092091099/The-Big-Bad-Wolf-Romance-Compilation-The-Big-Bad-Wolf-1-4-by-Heather-Killough-Walden.pdf
    • http://loaminoo.linkpc.net/5098099096093/Wolf-Willow-by-Wallace-Stegner.pdf
    • http://loaminoo.linkpc.net/4095096092090090/The-Long-Ride-White-Wolves-MC-3-by-Amy-Love.pdf
    • http://loaminoo.linkpc.net/9095098095099/Wolf-Among-Wolves-by-Hans-Fallada.pdf
    • http://loaminoo.linkpc.net/9096092094092093/Wolf-Among-Wolves-by-Hans-Fallada.pdf
    • http://loaminoo.linkpc.net/1098099091090097/The-Last-Wolf-The-Legend-of-All-Wolves-1-by-Maria-Vale.pdf
    • http://loaminoo.linkpc.net/3094092094098093/Watch-Wolf-Wolves-of-the-Beyond-3-by-Kathryn-Lasky.pdf
    • http://loaminoo.linkpc.net/1098098098090090/A-Wolf-Apart-The-Legend-of-All-Wolves-2-by-Maria-Vale.pdf
    • http://loaminoo.linkpc.net/4096096099095/Shadow-Wolf-Wolves-of-the-Beyond-2-by-Kathryn-Lasky.pdf
    • http://loaminoo.linkpc.net/2091093092097093/Behind-the-Curtain-Soulgirls-5-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/5095092096098096/Max-and-Milo-Go-to-Sleep-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/9098092099093092/Hunting-Wolf-Black-Mesa-Wolves-3-by-J-K-Harper.pdf
    • http://loaminoo.linkpc.net/3092092098090093/Claimed-by-the-Wolf-Channing-s-Wolves-1-by-Taylor-McKay.pdf
    • http://loaminoo.linkpc.net/9096092094