Malicious PDF — malware analysis report

Static analysis result for SHA-256 fdc1b0e651bac1d1…

MALICIOUS

PDF

13.7 KB Created: 2019-04-30 17:18:27 +01:00 Authoring application: mPDF 5.7
MD5: 3a177629ecc5c8b99e0f959b4c92e684 SHA-1: a2fcf31bacd100fac79e9ebcd1044fd9f0e191a3 SHA-256: fdc1b0e651bac1d165546ae1a137a6d04897de88a77269ed6f02ce2386e57cfe
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. The embedded URLs, such as http://loaminoo.linkpc.net/1090094094092/Bared-to-You-Crossfire-1-by-Sylvia-Day.pdf, are likely used to distribute further malicious content or for SEO spam purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090094094092/Bared-to-You-Crossfire-1-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/4094091095099092/Bared-to-You-Crossfire-1-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/3092095092096090/Bared-to-You-Crossfire-1-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/1094098093090095/Sylvia-Day-Crossfire-Series-4-Volume-Boxed-Set-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/3090090098091090/Bared-to-Him-by-Sierra-Cartwright.pdf
    • http://loaminoo.linkpc.net/2098092093098092/The-Way-We-Bared-Our-Souls-by-Willa-Strayhorn.pdf
    • http://loaminoo.linkpc.net/1099094096099098/The-Way-We-Bared-Our-Souls-by-Willa-Strayhorn.pdf
    • http://loaminoo.linkpc.net/1098094096091099/Bared-for-Her-Bear-Wylde-Bears-1-by-Jenika-Snow.pdf
    • http://loaminoo.linkpc.net/7093090099092/The-Element-of-Lavishness-Letters-of-William-Maxwell-and-Sylvia-Townsend-Warner-1938-1978-by-Sylvia-Townsend-Warner.pdf
    • http://loaminoo.linkpc.net/2092093092095091/Sylvia-Browne-s-Lessons-for-Life-by-Sylvia-Browne.pdf
    • http://loaminoo.linkpc.net/3096090090098/The-Unabridged-Journals-of-Sylvia-Plath-by-Sylvia-Plath.pdf
    • http://loaminoo.linkpc.net/3092096099090096/Bared-Blade-Fallen-Blade-2-by-Kelly-McCullough.pdf
    • http://loaminoo.linkpc.net/9098094092090099/The-Diaries-of-Sylvia-Townsend-Warner-by-Sylvia-Townsend-Warner.pdf
    • http://loaminoo.linkpc.net/3093095099093093/Ask-for-It-Georgian-1-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/3099090093091097/Ask-For-It-Georgian-1-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/3092090099094090/Just-Ask-Us-by-Sylvia-Olsen.pdf
    • http://loaminoo.linkpc.net/2090097090098/Ask-For-It-Georgian-1-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/2090092094094099/Seven-Years-to-Sin-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/9096097099096093/Afterburn-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/3091091097094097/Sam-and-Ben-by-Sylvia-Westphal.pdf
    • http://loaminoo.linkpc.net/3096090090098