Malicious PDF — malware analysis report

Static analysis result for SHA-256 debc9a40df394d4d…

MALICIOUS

PDF

14.9 KB Created: 2019-05-07 09:24:54 +01:00 Authoring application: mPDF 5.7
MD5: e76acc9481344b210dd3bba4f71e1d10 SHA-1: 14e6a18cebdc83d60fe41f3eb144284e420a7831 SHA-256: debc9a40df394d4dbd355605f32d7e33b04630d846fd87f17ff27d6b6036b092
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded external links, forming a link farm. The primary heuristic indicates this is a PDF SEO link farm, suggesting a malicious intent to drive traffic or distribute further content. While the specific URLs are marked as benign, the sheer volume and structure point towards a malicious distribution or redirection scheme. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7091090091091096/Histoires-de-mer-et-de-pirates-52-histoires-by-Rapha-le-Glaux.pdf
    • http://loaminoo.linkpc.net/7099096091098093/Histoires-de-No-l-Histoires-raconter-pour-les-b-b-s-by-Delphine-Bolin.pdf
    • http://loaminoo.linkpc.net/7099096091098092/Histoires-pour-s-endormir-by-Raffaella.pdf
    • http://loaminoo.linkpc.net/6091091092092098/Osez-20-histoires-de-chasseuses-d-hommes-by-Various.pdf
    • http://loaminoo.linkpc.net/8091093090098095/Histoires-miraculeuses-by-Danielle-Goyette.pdf
    • http://loaminoo.linkpc.net/8090099099095093/Les-Histoires-Les-5-tomes-au-complet-by-Tacite.pdf
    • http://loaminoo.linkpc.net/6099097091090092/Aaron-Histoires-de-Survivants-t-1-by-J-P-Barnaby.pdf
    • http://loaminoo.linkpc.net/6090098097099098/Osez-20-histoires-de-soumission-et-domination-by-Collectif.pdf
    • http://loaminoo.linkpc.net/8093099091092090/Les-Meilleures-Histoires-Droles-by-Petit-Tamis.pdf
    • http://loaminoo.linkpc.net/7090098093095094/Histoires-entre-meutes-by-James-Hawk.pdf
    • http://loaminoo.linkpc.net/7092098097093094/Voyeuse-Histoires-rotique-t-1-by-Lul-Sanz.pdf
    • http://loaminoo.linkpc.net/6099090096093097/Nouvelles-Histoires-de-Fraudeurs-by-Michel-Loosen.pdf
    • http://loaminoo.linkpc.net/1091091098096095091/Premiers-pas-d-un-h-t-ro-Histoires-inavouables-t-11-by-Antonin-Evergreen.pdf
    • http://loaminoo.linkpc.net/7095091099099092/Ou-Vont-Les-Sizerins-Flammes-En-Ete-Histoires-by-Robert-Lalonde.pdf
    • http://loaminoo.linkpc.net/5097096095099092/3-Histoires-Secretes-De-Sherlock-Holmes-by-Ren-Reouven.pdf
    • http://loaminoo.linkpc.net/7097091092098090/Les-meilleures-histoires-d-amour-rotiques-by-June-Moore.pdf
    • http://loaminoo.linkpc.net/8091099092094094/Osez-20-histoires-de-sexe-partout-sauf-dans-un-lit-by-Various.pdf
    • http://loaminoo.linkpc.net/5099092090099093/Minet-gay-adepte-de-la-fess-e-Histoires-inavouables-t-2-by-Antonin-Evergreen.pdf
    • http://loaminoo.linkpc.net/6092096093091091/Oncle-de-la-ville-histoires-courtes-pour-les-enfants-t-13-by-Mirjana-Aissaoui.pdf
    • http://loaminoo.linkpc.net/6095092090094097/Oedipe-le-maudit-Histoires-Noires-de-la-Mythologie-by-Marie-Th-r-se-Davidson.pdf
    • http://loaminoo.linkpc.net/60990900