Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3d7a60e35d424ab…

MALICIOUS

PDF

17.0 KB Created: 2019-04-30 04:58:54 +01:00 Authoring application: mPDF 5.7
MD5: d0b237ff08ab12e0ce0bbc3aed1500f9 SHA-1: 108ff585ad21cacf90462bbae79c1d2030bc9c3f SHA-256: d3d7a60e35d424ab19e03e1f0b685b62e47590ab29d9b3c98952c87035523eb2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged the document as malicious. While the URLs themselves are currently marked as benign, the sheer volume and the heuristic firing suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3093092098098096/Surf-amp-Surrender-Summer-Love-2-by-Riley-Edgewood.pdf
    • http://loaminoo.linkpc.net/1094095097095098/VIP-Rock-amp-Release-Act-1-by-Riley-Edgewood.pdf
    • http://loaminoo.linkpc.net/2096090091098090/Reclaimed-Surrender-Trust-in-Me-1-by-Riley-Murphy.pdf
    • http://loaminoo.linkpc.net/2098090095094098/Requested-Surrender-Trust-in-Me-4-by-Riley-Murphy.pdf
    • http://loaminoo.linkpc.net/1097090091093096/Required-Surrender-Trust-in-Me-3-by-Riley-Murphy.pdf
    • http://loaminoo.linkpc.net/1090093093094/Surrender-Your-Love-Surrender-Your-Love-1-by-J-C-Reed.pdf
    • http://loaminoo.linkpc.net/7094091099097095/Hot-Summer-Love-Box-Set-Five-Full-Length-Sexy-amp-Seductive-Summer-Sizzles-by-Cali-MacKay.pdf
    • http://loaminoo.linkpc.net/6090090097096/Dark-Surf-Dark-Surf-1-by-T-C-Zmak.pdf
    • http://loaminoo.linkpc.net/8096098094094096/Surrender-your-Love---Ergeben-by-J-C-Reed.pdf
    • http://loaminoo.linkpc.net/4098095096097091/No-Surrender-Love-United-2-by-Melyssa-Winchester.pdf
    • http://loaminoo.linkpc.net/1094097090098099/Surrender-to-Love-Night-Calls-3-by-J-C-Valentine.pdf
    • http://loaminoo.linkpc.net/9097095095095097/Predaj-se-ljubavi-Surrender-Your-Love-1-by-J-C-Reed.pdf
    • http://loaminoo.linkpc.net/9097095095096092/Osvoji-ljubav-Surrender-Your-Love-2-by-J-C-Reed.pdf
    • http://loaminoo.linkpc.net/1099098092095098/Summer-of-Love-The-Principles-of-Love-5-by-Emily-Franklin.pdf
    • http://loaminoo.linkpc.net/2098091096099098/Love-Of-My-Only-Lifetime-Embrace-Your-Soul-3-by-Riley-Murphy.pdf
    • http://loaminoo.linkpc.net/3095094099092098/The-Bittersweet-Bride-Advertisements-for-Love-1-by-Vanessa-Riley.pdf
    • http://loaminoo.linkpc.net/2098091094091094/Love-Of-My-Every-Lifetime-Embrace-Your-Soul-2-by-Riley-Murphy.pdf
    • http://loaminoo.linkpc.net/3096093094093092/a-little-book-about-believing-The-Transformative-Healing-Power-of-Faith-Love-and-Surrender-by-Cash-Peters.pdf
    • http://loaminoo.linkpc.net/4090092090097091/Absolution-Edgewood-3-by-Karen-McQuestion.pdf
    • http://loaminoo.linkpc.net/4097091090090093/Love-and-Glory-Silhouette-By-Request-3-s-A-Question-of-Honor-No-Surrender-Return-of-a-Hero-by-Lindsay-McKenna.pdf
    • http://loaminoo.linkpc.net/80960980