Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7118c58d85db515…

MALICIOUS

PDF

16.8 KB Created: 2019-05-05 15:54:50 +01:00 Authoring application: mPDF 5.7
MD5: c9285cd104ae94e2ce349e59e863cc3e SHA-1: 2709b659c612b423dbc1eef0e3a268bb16a349b4 SHA-256: e7118c58d85db515376acef31bed2dd0a26e03401a94dff869f3c769c9287e22
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm with 22 external PDF links, as detected by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded URLs, while individually marked as benign, collectively form a pattern indicative of a malicious distribution or redirection scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3094094099098094/Payback-and-a-Bottle-of-Merlot-Like-Sisters-1-by-Bria-Marche.pdf
    • http://loaminoo.linkpc.net/7090097095098090/Marche-et-invente-ta-vie-Adolescents-en-difficult-ils-se-reconstruisent-par-une-marche-au-long-cours-by-Bernard-Ollivier.pdf
    • http://loaminoo.linkpc.net/7095093099090098/Payback-is-a-Bitch-Payback-Vengence-Book-1-by-Douglas-Ewan-Cameron.pdf
    • http://loaminoo.linkpc.net/4093098094090096/The-Message-in-a-Bottle-Romance-Collection-Hope-Reaches-Across-the-Centuries-Through-One-Single-Bottle-Inspiring-Five-Romances-by-Joanne-Bischof.pdf
    • http://loaminoo.linkpc.net/3098093090096092/Lover-in-a-Bottle-In-a-Bottle-3-by-Shona-Husk.pdf
    • http://loaminoo.linkpc.net/2099096099093096/A-Trade-for-Good-by-Bria-Daly.pdf
    • http://loaminoo.linkpc.net/2091097090098093/The-Catching-Kind-Brew-Ha-Ha-3-by-Bria-Quinlan.pdf
    • http://loaminoo.linkpc.net/1091094096098/Worth-the-Fall-Brew-Ha-Ha-2-by-Bria-Quinlan.pdf
    • http://loaminoo.linkpc.net/1099098096092090/Secret-Girlfriend-RVHS-Secrets-1-by-Bria-Quinlan.pdf
    • http://loaminoo.linkpc.net/1092092092090098/Crimson-Savior-Hell-s-Guardian-Chronicles-1-by-Bria-Lexor.pdf
    • http://loaminoo.linkpc.net/7096097094098097/Galop---Marche-by-LAVIGNAC-Albert.pdf
    • http://loaminoo.linkpc.net/5093097097093090/Marche-ou-cr-ve-by-GERARD-THOLANCE.pdf
    • http://loaminoo.linkpc.net/2096097092093092/How-Shakespeare-Changed-Everything-by-Stephen-Marche.pdf
    • http://loaminoo.linkpc.net/1097095091093091/Sisters-of-Salt-and-Iron-The-Sisters-of-Blood-and-Spirit-2-by-Kady-Cross.pdf
    • http://loaminoo.linkpc.net/8090093095094097/Ne-marche-pas-si-tu-peux-danser-by-Anne-Van-Stappen.pdf
    • http://loaminoo.linkpc.net/6091094098099097/Notre-R--EVOLUTION-est-en-marche-by-Alain-GROULT.pdf
    • http://loaminoo.linkpc.net/7098093091095096/L-Autre-Afrique-Entre-Don-Et-Marche-by-Serge-Latouche.pdf
    • http://loaminoo.linkpc.net/6092099092091091/Demain-Un-nouveau-monde-en-marche-by-Cyril-Dion.pdf
    • http://loaminoo.linkpc.net/1092093090094093/Sisters-in-Love-Snow-Sisters-1-by-Melissa-Foster.pdf
    • http://loaminoo.linkpc.net/7094090098094097/Bodhicary-vat-ra-la-marche-vers-l-Eveil-Nouvelle-traduction-by-ntideva.pdf
    • http://loaminoo.linkpc.net/2091097090098093/The-Catching-Kind-Brew-Ha-Ha-3-by-Bria-Quin