Malicious PDF — malware analysis report

Static analysis result for SHA-256 f73c0c134dedc6eb…

MALICIOUS

PDF

15.7 KB Created: 2019-05-03 05:02:59 +01:00 Authoring application: mPDF 5.7
MD5: c1edb6516c8b0b89e63d3ade0ee86e27 SHA-1: 9cc1daf51465d5a4a1f65288314e809389f74465 SHA-256: f73c0c134dedc6ebf3cb32e4bfa58ebef0355f38c639163be56ea45e7b67ed64
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to distribute further malware. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4096092097093092/Moonlight-Over-Manhattan-From-Manhattan-with-Love-6-by-Sarah-Morgan.pdf
    • http://loaminoo.linkpc.net/3093092097/Sleepless-in-Manhattan-From-Manhattan-with-Love-1-by-Sarah-Morgan.pdf
    • http://loaminoo.linkpc.net/1090096094091099090/Organize-Yourself-by-Ronni-Eisenberg.pdf
    • http://loaminoo.linkpc.net/2093096094091091/When-the-Stars-Lead-to-You-by-Ronni-Davis.pdf
    • http://loaminoo.linkpc.net/1090096094092096093/Organize-Your-Life-Free-Yourself-from-Clutter-and-Find-More-Personal-Time-by-Ronni-Eisenberg.pdf
    • http://loaminoo.linkpc.net/1098090097096096/Gods-of-Manhattan-Gods-of-Manhattan-1-by-Scott-Mebus.pdf
    • http://loaminoo.linkpc.net/2091091098091094/Secret-Intentions-Cooper-13-Cooper-Security-6-by-Paula-Graves.pdf
    • http://loaminoo.linkpc.net/3094094093094094/Darling-Monster-The-Letters-of-Lady-Diana-Cooper-to-her-Son-John-Julius-Norwich-1939-1952-by-Lady-Diana-Cooper.pdf
    • http://loaminoo.linkpc.net/3098095097091096/The-Cooper-Kids-The-Cooper-Kids-Adventures-1-4-by-Frank-E-Peretti.pdf
    • http://loaminoo.linkpc.net/3099090093093099/Down-and-Out-in-Manhattan-by-Irene-Magers.pdf
    • http://loaminoo.linkpc.net/3096091092097090/Zombies-Take-Manhattan-by-Marina-Bridges.pdf
    • http://loaminoo.linkpc.net/3095094093092090/Manhattan-Nocturne-by-Colin-Harrison.pdf
    • http://loaminoo.linkpc.net/6096096093096093/The-Vatican-Billions-by-Avro-Manhattan.pdf
    • http://loaminoo.linkpc.net/1094097099091099/Manhattan-Lovers-and-Liars-1-by-Liz-Meldon.pdf
    • http://loaminoo.linkpc.net/9092090097091094/M-nchen-Manhattan-1-by-Vanessa-Vollmann.pdf
    • http://loaminoo.linkpc.net/7095091099097097/Manhattan-Millionaire-s-Cinderella-by-Sun-Chara.pdf
    • http://loaminoo.linkpc.net/1093099093095093/Manhattan-Transfer-by-John-E-Stith.pdf
    • http://loaminoo.linkpc.net/3098097097092098/Murder-Becomes-Manhattan-by-Jeffrey-Eaton.pdf
    • http://loaminoo.linkpc.net/4091091090090092/It-Had-to-Be-You-Manhattan-1-by-Timothy-James-Beck.pdf
    • http://loaminoo.linkpc.net/2096093097094092/Manhattan-s-Babe-by-Frederic-Beigbeder.pdf