Malicious PDF — malware analysis report

Static analysis result for SHA-256 d93dfd9748b0a926…

MALICIOUS

PDF

14.9 KB Created: 2019-05-02 06:46:18 +01:00 Authoring application: mPDF 5.7
MD5: 2d2ef6119b8f51a9aa0be23603c6275b SHA-1: 9335500511a4ef0287e8641677295c7afd530fa1 SHA-256: d93dfd9748b0a926704d7a9c81cad41e99689ee85e88798eb82501bd1176302e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The primary heuristic indicates this is a technique to distribute malicious content or SEO spam. While the URLs themselves are marked as benign, the sheer volume and the critical heuristic firing suggest a malicious intent to redirect users. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9094098095091098/Intron-Depot-2-Blades-Intron-Depot-2-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/4099096090098/Intron-Depot-Intron-Depot-1-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/3093097091099098/Dominion-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/4094093095099099/Orion-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/9094098095093093/Pandora-in-the-Crimson-Shell-Ghost-Urn-Vol-3-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/9094098096092092/Robot-Rondo-Ghost-in-the-Shell-6-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/9094098096092096/Ghost-in-the-Shell-01-Brennende-Stadt-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/9094098095093095/Pandora-in-the-Crimson-Shell-Ghost-Urn-Vol-4-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/9094098096091094/Brain-Drain-Ghost-in-the-Shell-7-8-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/9094098097092090/Ghost-in-the-Shell-Official-Art-Book-Playstation-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/8092092095093/Appleseed-The-Scales-of-Prometheus-Appleseed-3-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/1090092093098090095/Appleseed-Vol-1-and-2-Appleseed-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/9094098095092093/Dokuganryu-Masamune-quot-Kita-no-Hasha-quot-Date-Masamune-no-Yabou-by-Bessatsu-Rekishi-Tokuhon.pdf
    • http://loaminoo.linkpc.net/9094098094091094/Masamune-kun-no-Revenge-Vol-06-Masamune-kun-no-Revenge-6-by-Hazuki-Takeoka.pdf
    • http://loaminoo.linkpc.net/9094098096092091/Masamune-Hakucho-Sakka-no-jiden-by-Hakuch-Masamune.pdf
    • http://loaminoo.linkpc.net/4094092095093094/RWBY-by-Shirow-Miwa.pdf
    • http://loaminoo.linkpc.net/2092098095095099/Dogs-Bullets-amp-Carnage-Vol-4-by-Shirow-Miwa.pdf
    • http://loaminoo.linkpc.net/1091095090098096097/Dogs-Bullets-amp-Carnage-Vol-5-by-Shirow-Miwa.pdf
    • http://loaminoo.linkpc.net/9094098096092093/The-Rastafarian-Movement-by-Sakura-Masamune.pdf
    • http://loaminoo.linkpc.net/9094098097092095/--3-Masamune-kun-no-Revenge-3-by-Hazuki-Takeoka.pdf
    • http://loaminoo.linkpc.net/8092092095093/Appleseed-The-S