Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3481281e85cc555…

MALICIOUS

PDF

15.5 KB Created: 2019-05-22 07:54:59 +01:00 Authoring application: mPDF 5.7
MD5: 32e7c8d144de2dfd75e9583adf6aec91 SHA-1: 60e3fd76f78113ec87f83a1fa3475242ac4a7ad2 SHA-256: e3481281e85cc555941819f9680361efb40ae831c97b6227358bebaedaeaaa96
130 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The PDF contains a launch action that redirects to a link farm of 21 external PDF documents, indicating a malicious intent to distribute further content. The ML classifier strongly flagged this PDF as malicious. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9970

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Launch action high PDF_LAUNCH
    PDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091098099099099090/Slocum-and-the-Grizzly-Flats-Killers-Slocum-408-by-Jake-Logan.pdf
    • http://loaminoo.linkpc.net/3097095092096099/Made-to-Order-Family-Slocum-Family-3-by-Ruth-Logan-Herne.pdf
    • http://loaminoo.linkpc.net/9094096096092095/Sailing-Alone-Around-the-World-by-Joshua-Slocum.pdf
    • http://loaminoo.linkpc.net/1090094094090093096/General-Slocum-s-Gold-by-Nicholas-Kaufmann.pdf
    • http://loaminoo.linkpc.net/2099091099090090/Sisters-of-Mercy-Flats-Sisters-of-Mercy-Flats-1-by-Lori-Copeland.pdf
    • http://loaminoo.linkpc.net/3097093091094094/Logan-s-Chef-Notes-amp-Half-Baked-Tales-Cooking-Dreams-by-Logan-Guleff.pdf
    • http://loaminoo.linkpc.net/7096090092095090/Serial-Killers-Trends-Motives-and-Famous-Serial-Killers-Including-Ted-Kaczynski-Ted-Bundy-and-the-Zodiac-Killer-by-Kaelyn-Smith.pdf
    • http://loaminoo.linkpc.net/9097092094093091/Logan-s-World-Logan-2-by-William-F-Nolan.pdf
    • http://loaminoo.linkpc.net/3090091095097098/Logan-s-Search-Logan-s-Run-3-by-William-F-Nolan.pdf
    • http://loaminoo.linkpc.net/4091098099094097/Jackass-Flats-by-Julia-Talbot.pdf
    • http://loaminoo.linkpc.net/3098090092093090/Just-Jake-Just-Jake-1-by-Jake-Marcionette.pdf
    • http://loaminoo.linkpc.net/1093099092099095/Sanibel-Flats-Doc-Ford-1-by-Randy-Wayne-White.pdf
    • http://loaminoo.linkpc.net/3093095090091095/Fabulous-in-Flats-Putting-My-Best-Foot-Forward-by-Mary-T-Wagner.pdf
    • http://loaminoo.linkpc.net/1090094091091/I-Hunt-Killers-I-Hunt-Killers-1-by-Barry-Lyga.pdf
    • http://loaminoo.linkpc.net/2096096099090090/I-Hunt-Killers-I-Hunt-Killers-1-by-Barry-Lyga.pdf
    • http://loaminoo.linkpc.net/1090090096092099092/The-Ghost-at-His-Back-Rankin-Flats-Supernatural-Thrillers-1-by-Cameron-Lowe.pdf
    • http://loaminoo.linkpc.net/1094095096096/The-Grizzly-by-Annabel-Johnson.pdf
    • http://loaminoo.linkpc.net/3095093097094099/Launch-the-Hunt-Grizzly-Rim-1-by-Mia-West.pdf
    • http://loaminoo.linkpc.net/3099092090096096/Nothin-But-Trouble-The-Grizzly-MC-4-by-Jenika-Snow.pdf
    • http://loaminoo.linkpc.net/4098094090090097/Unbearable-Arms-Grizzly-Next-Door-4-by-Aya-Morningstar.pdf
    • http://loaminoo.linkpc.net/3090091095097098/Logan-s-Search-Logan-s-Run-3-by-Willia