Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4ab6eedaf743957…

MALICIOUS

PDF

19.0 KB Created: 2019-05-01 08:07:31 +01:00 Authoring application: mPDF 5.7
MD5: 394b67bfc15c76e705be71bdf329660c SHA-1: f8670a2b86f709fdf0e45d6b173d33a4eb9d49d3 SHA-256: e4ab6eedaf7439574468aa1254afa098fe9ed5e4921caea037502d04d79f87e8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to a domain that hosts numerous PDF files. The ML classifier also flagged this PDF as malicious. The embedded links likely serve as a lure to direct users to potentially malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1095097098098092/Kingdom-s-Edge-Kingdom-3-by-Chuck-Black.pdf
    • http://loaminoo.linkpc.net/1090093091098091/Kingdom-s-Hope-Kingdom-2-by-Chuck-Black.pdf
    • http://loaminoo.linkpc.net/1090093093098095/Kingdom-s-Call-Kingdom-4-by-Chuck-Black.pdf
    • http://loaminoo.linkpc.net/7097093096090099/Kingdom-Principles-Preparing-for-Kingdom-Experience-and-Expansion-by-Myles-Munroe.pdf
    • http://loaminoo.linkpc.net/1095090092099096/Of-Such-Is-the-Kingdom-Parts-I-amp-II-A-Novel-of-the-Christ-and-the-Roman-Empire-Kingdom-1-by-James-M-Becher.pdf
    • http://loaminoo.linkpc.net/1093098099099096/The-Greatness-of-the-Kingdom-An-Inductive-Study-of-the-Kingdom-of-God-by-Alva-J-McClain.pdf
    • http://loaminoo.linkpc.net/1095090096098097/Of-Such-Is-The-Kingdom-Part-III-Kingdom-3-by-James-M-Becher.pdf
    • http://loaminoo.linkpc.net/1096091093093092/Articles-on-Old-Kingdom-Series-Including-Sabriel-Lirael-Abhorsen-Across-the-Wall-A-Tale-of-the-Abhorsen-and-Other-Stories-Old-Kingdom-Book-Ser-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/6095095099098094/Magic-Kingdom---Foreclosed-A-Spoof-Based-on-Terry-Brooks-Magic-Kingdom-for-Sale-From-the-Author-of-the-Frontmire-Histories-by-David-E-Daigle.pdf
    • http://loaminoo.linkpc.net/5097093092097/The-Quest-for-Paradise-The-Return-to-the-Kingdom-of-Fantasy-The-Kingdom-of-Fantasy-2-by-Geronimo-Stilton.pdf
    • http://loaminoo.linkpc.net/1096099098096096/The-Hollow-Kingdom-The-Hollow-Kingdom-Trilogy-Book-I-by-Clare-B-Dunkle.pdf
    • http://loaminoo.linkpc.net/4094092098092094/Kingdom-Hearts-The-Complete-Series-Kingdom-Hearts-1-4-by-Shiro-Amano.pdf
    • http://loaminoo.linkpc.net/1090093093099095092/Kingdom-of-Abel---Bathed-in-Shadow-Kingdom-of-Abel-3-by-Gume-Laurel-III.pdf
    • http://loaminoo.linkpc.net/1090093094090090095/Kingdom-of-Abel---Song-of-the-Silent-Kingdom-of-Abel-2-by-Gume-Laurel-III.pdf
    • http://loaminoo.linkpc.net/1090093093099093093/Kingdom-of-Abel---A-Journey-Not-Their-Own-Kingdom-of-Abel-1-by-Gume-Laurel-III.pdf
    • http://loaminoo.linkpc.net/2090094090097097/Kingdom-Hearts-Vol-4-Kingdom-Hearts-4-by-Shiro-Amano.pdf
    • http://loaminoo.linkpc.net/3098094099097/The-Kingdom-of-God-Is-Within-You-by-Leo-Tolstoy.pdf
    • http://loaminoo.linkpc.net/1095093091091093/The-Kingdom-of-the-Air-by-C-T-Wells.pdf
    • http://loaminoo.linkpc.net/1097097098094090/The-Kingdom-by-Guy-S-Stanton-III.pdf
    • http://loaminoo.linkpc.net/8097098094098099/The-Kingdom-of-God-Is-Within-You-by-Leo-Tolstoy.pdf
    • http://loaminoo.linkpc.net/1096091093093092/Articles-on-Old-Kingdom-Series-Including-Sabr