Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4a48f030236b49b…

MALICIOUS

PDF

13.7 KB Created: 2019-04-30 05:36:10 +01:00 Authoring application: mPDF 5.7
MD5: af8c80e6b24fc6d4efbf63384c648d6a SHA-1: c98e113a44dc671285af99dae3a7d14c36d2c05c SHA-256: e4a48f030236b49be9e0cdb3e3b8955238b3948c5f9beb451ce8e2a9d6e0e792
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic, which likely serve as a lure to external malicious content. The specific URLs extracted point to a domain that appears to be used for hosting or redirecting to potentially harmful files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097094093097097/Spear---A-Spear-in-Flight-Spear-1-by-Douglas-Owen.pdf
    • http://loaminoo.linkpc.net/6097094090092099/Club-Libertine-Box-Set-Volume-4-Club-Libertine-7-8-by-Diane-Leyne.pdf
    • http://loaminoo.linkpc.net/9098096099099092/Sacrifice-Ophelia-Lind-2-by-Peta-Crake.pdf
    • http://loaminoo.linkpc.net/9095093093093095/Feminist-Research-Prospect-and-Retrospect-by-Peta-Tancred-Sheriff.pdf
    • http://loaminoo.linkpc.net/2090090099092098/Chamber-of-Bears-The-Dawn-of-Man-Peta-s-Story-Book2-by-Avery-Kloss.pdf
    • http://loaminoo.linkpc.net/6097094090091094/The-Libertine-by-Kathy-Berry.pdf
    • http://loaminoo.linkpc.net/6097094090091099/The-Libertine-by-Robert-Desmond.pdf
    • http://loaminoo.linkpc.net/6097093099092098/Libertine-in-Love-by-Caroline-Courtney.pdf
    • http://loaminoo.linkpc.net/6097093099096092/The-Libertine-Belles-by-Linnet-Moss.pdf
    • http://loaminoo.linkpc.net/6097093098098090/Libertine-Awakenings-A-Psychosexual-Odyssey-by-Cat-Ravenelle.pdf
    • http://loaminoo.linkpc.net/2099099092092098/The-Dom-the-Switch-and-the-Sub-Club-Libertine-5-by-Diane-Leyne.pdf
    • http://loaminoo.linkpc.net/6097093099096094/Libertine-in-the-Tudor-Court-by-Juliet-Landon.pdf
    • http://loaminoo.linkpc.net/6097093099099098/The-Rival-Widows-or-Fair-Libertine-by-Elizabeth-Cooper.pdf
    • http://loaminoo.linkpc.net/6097093099097092/The-Picture-of-Submission-Libertine-Island-4-by-Diane-Leyne.pdf
    • http://loaminoo.linkpc.net/6095090094097090/Pleasures-and-Follies-of-a-Goodnatured-Libertine-by-R-tif-de-la-Bretonne.pdf
    • http://loaminoo.linkpc.net/2093095090098097/The-Innocent-Libertine-Heirs-of-Acadia-2-by-T-Davis-Bunn.pdf
    • http://loaminoo.linkpc.net/3094090099099091/The-Undoing-of-a-Libertine-Somerset-Historical-Romance-2-by-Raine-Miller.pdf
    • http://loaminoo.linkpc.net/6097094090092094/The-Libertine-The-Art-of-Love-in-Eighteenth-Century-France-by-Michel-Delon.pdf
    • http://loaminoo.linkpc.net/4098094093095091/The-Spear-by-James-Herbert.pdf
    • http://loaminoo.linkpc.net/1092091094094098/Escape-Tip-of-the-Spear-1-by-Belle-Ami.pdf