Malicious PDF — malware analysis report

Static analysis result for SHA-256 edfd9614e84494e1…

MALICIOUS

PDF

25.8 KB Created: 2019-04-30 04:38:45 +01:00 Authoring application: mPDF 5.7
MD5: b1e69aa7039b850e9d99c0e06d22c7bf SHA-1: 6db6799c9c5428a50c98579b51bd120366496ea3 SHA-256: edfd9614e84494e171d24ab37310a96c1d60b521282c3c29caaea9dab73c606f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. While the extracted URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely to direct users to potentially harmful content or for SEO abuse. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099091098097/The-Man-Who-Loved-Jane-Austen-The-Man-Who-Loved-Jane-Austen-1-by-Sally-Smith-O-39-Rourke.pdf
    • http://loaminoo.linkpc.net/8095098091095096/Persuasion-Special-Annotated-Edition-The-World-of-Jane-Austen-6-The-World-of-Jane-Austen-Series-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1091097097091090093/Four-Major-Works-by-Jane-Austen-Northanger-Abbey-Lady-Susan-Sense-and-Sensibility-Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1091097097090097096/Jane-Austen-Four-Novels-Sense-and-Sensibility-Pride-and-Prejudice-Emma-Northanger-Abbey-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/8097090092095/The-Complete-Novels-of-Jane-Austen-Volume-II-Emma-Northanger-Abbey-Persuasion-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1091097096099092097/The-Illustrated-Works-Of-Jane-Austen-Sense-and-Sensibility-Emma-Northanger-Abbey-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/5097092090099092/MANSFIELD-PARK---JANE-AUSTEN-WITH-NOTES-BIOGRAPHY-ILLUSTRATED-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/9091095097090/Jane-Austen-Pride-and-Prejudice-Mansfield-Park-Persuasion-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/5095098094096095/The-Novels-of-Jane-Austen-Northanger-Abbey-In-Ten-Volumes-Vol-IX-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/5093091098097094/NORTHANGER-ABBEY-by-Jane-Austen-author-of-Sense-and-Sensibility-Pride-and-Prejudice-Persuasion-Emma-Mansfield-Park-Nothanger-Abbey-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/6090095091095093/L-Abbaye-de-Northanger---Le-seul-roman-gothique-de-Jane-Austen-L-dition-int-grale-Northanger-Abbey-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1096095092093090/Rude-Awakenings-of-a-Jane-Austen-Addict-Jane-Austen-Addict-2-by-Laurie-Viera-Rigler.pdf
    • http://loaminoo.linkpc.net/6092096092099099/SENSE-AND-SENSIBILITY-by-Jane-Austen-author-of-Mansfield-Park-Persuasion-Sense-and-Sensibility-Northanger-Pride-and-Prejudice-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/6097093092096091/PRIDE-AND-PREJUDICE-Jane-Austen-author-of-Mansfield-Park-Persuasion-Sense-and-Sensibility-Northanger-Pride-and-Prejudice-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/8096094099093/Confessions-of-a-Jane-Austen-Addict-Jane-Austen-Addict-1-by-Laurie-Viera-Rigler.pdf
    • http://loaminoo.linkpc.net/5094093092095096/The-Novels-of-Jane-Austen-Volume-7-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/2090091099090096/Complete-Novels-Of-Jane-Austen-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/4098093091090090/Jane-Austen-Complete-and-Unabridged-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/2097097094090091/The-Complete-Novels-of-Jane-Austen-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/3098099095091092/The-Three-Colonels-Jane-Austen-s-Fighting-Men-Jane-Austen-s-Fighting-Men-1-by-Jack-Caldwell.pdf
    • http://loaminoo.linkpc.net/1091097097090097096/Jane-Austen-Four-Novels-Sense-and-Sensibility-Pride-and-Prejudice-Emma-Northange