Malicious PDF — malware analysis report

Static analysis result for SHA-256 e27bcaef7c4b2ffc…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 05:57:57 +01:00 Authoring application: mPDF 5.7
MD5: 2e43ce602324be51f9f2034688071c3c SHA-1: ecfc963d283c156bb60ad366fe8a22b5da1f704e SHA-256: e27bcaef7c4b2ffc8046677cd5d1b3dd4f8cfdad1c31a27732e72a2fac555461
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged as malicious by an ML classifier and contains a large number of embedded links, many of which point to the same domain. This behavior is consistent with SEO link farming or a distribution mechanism for malicious content. The document body was unreadable, but the heuristic firings strongly indicate a malicious intent related to the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4094093090092099/Here-and-Now-Complete-Series-Here-and-Now-1-3-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/2092096099093098/Here-and-Now-Complete-Series-Here-and-Now-1-3-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/1097094092094092/All-for-This-Here-and-Now-3-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/7094092096098/Lost-in-Me-Here-and-Now-1-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/1091093098092097097/Here-and-Now-Einsamkeit-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/7094091092094092/Unbreak-Me-T02-Si-seulement-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/3096098094096093/Something-Wild-Reckless-amp-Real-0-5-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/8094092096097095/Unbreak-Me-T03-R-ves-vol-s-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/1094097091092092/Billionaire-Romance-Complete-Series-Alpha-Male-Romances-Suspenseful-Alpha-Male-Billionaire-Bad-Boy-Romance-Billionaire-Series-by-J-L-Ryan.pdf
    • http://loaminoo.linkpc.net/3099096094096099/Something-Real-Reckless-amp-Real-2-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/9090090098099095/The-Volkov-Brothers-Series-The-Complete-Series-by-Leslie-North.pdf
    • http://loaminoo.linkpc.net/6094096092094095/Saved-Part-Two-The-Saved-Series-Book-2-by-Lexi-Larue.pdf
    • http://loaminoo.linkpc.net/4097097091093092/Universe-Online---Enter-the-Game-Complete-Edition-by-Ryan-39-Viken-39-Henning.pdf
    • http://loaminoo.linkpc.net/3096091090090091/Zombie-D-O-A-Series-Three-The-Complete-Series-Three-by-J-J-Zep.pdf
    • http://loaminoo.linkpc.net/9090099091092/The-Complete-Little-Women-Series-Little-Women-Good-Wives-Little-Men-Jo-s-Boys-The-Beloved-Classics-of-American-Literature-The-coming-of-age-series-experiences-with-her-three-sisters-by-Louisa-May-Alcott.pdf
    • http://loaminoo.linkpc.net/4091099090094093/The-Undead-World-of-Oz-L-Frank-Baum-s-the-Wonderful-Wizard-of-Oz-Complete-with-Zombies-and-Monsters-by-Ryan-C-Thomas.pdf
    • http://loaminoo.linkpc.net/3095094090092096/Complete-Harlow-Series-Beneath-Him-Embracing-Him-Completing-Him-Harlow-Series-1-3-by-C-Shell.pdf
    • http://loaminoo.linkpc.net/1095096098092098/Sign-Of-The-Guardian-Volume-II-in-the-First-Life-fantasy-adventure-series-by-Ryan-Logan.pdf
    • http://loaminoo.linkpc.net/3091090095091094/The-Complete-Now-Series-Now-1-3-by-Brenda-Rothert.pdf
    • http://loaminoo.linkpc.net/2091096096099091/The-Complete-Secrets-Series-by-L-K-Shaw.pdf