Malicious PDF — malware analysis report

Static analysis result for SHA-256 06b2a7ce8860d0ab…

MALICIOUS

PDF

15.9 KB Created: 2019-04-29 23:24:18 +01:00 Authoring application: mPDF 5.7
MD5: 6888a541f1b0402d9b75db13c1e0e8fe SHA-1: 6f980201cf367988f3dea5a3edfb6f0fe9803061 SHA-256: 06b2a7ce8860d0ab224531b082b4fe540dd80f322658eeac1731eedf4137c7f6
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. While no scripts were explicitly extracted, the ML classifier and the PDF_SEO_LINK_FARM heuristic strongly indicate malicious intent. The embedded URLs, despite being labeled as benign in isolation, contribute to the overall suspicious nature of the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099096093092090/Retribution-Anna-Strong-Chronicles-5-by-Jeanne-C-Stein.pdf
    • http://loaminoo.linkpc.net/1099096091092091/Chosen-Anna-Strong-Chronicles-6-by-Jeanne-C-Stein.pdf
    • http://loaminoo.linkpc.net/1091096097097096/Legacy-Anna-Strong-Chronicles-4-by-Jeanne-C-Stein.pdf
    • http://loaminoo.linkpc.net/1091092092096091092/Cloud-City-Anna-Strong-Chronicles-8-5-by-Jeanne-C-Stein.pdf
    • http://loaminoo.linkpc.net/1091096098091091/Blood-Drive-Anna-Strong-Chronicles-2-by-Jeanne-C-Stein.pdf
    • http://loaminoo.linkpc.net/1093095095099098/Blood-Bond-Anna-Strong-Chronicles-9-by-Jeanne-C-Stein.pdf
    • http://loaminoo.linkpc.net/3094097098096097/The-Age-of-Retribution-Master-Chronicles-8-by-Jamie-Craig.pdf
    • http://loaminoo.linkpc.net/2090096099094092/Retribution-The-Irin-Chronicles-1-A-DarkWorld-Series-by-T-G-Ayer.pdf
    • http://loaminoo.linkpc.net/2091093097097095/The-Grey-Heir-The-Edgewalker-Chronicles-Book-1-by-Zachary-Katz-Stein.pdf
    • http://loaminoo.linkpc.net/2097094096095091/Stein-on-Writing-A-Master-Editor-of-Some-of-the-Most-Successful-Writers-of-Our-Century-Shares-His-Craft-Techniques-and-Strategies-by-Sol-Stein.pdf
    • http://loaminoo.linkpc.net/7096096095093/Strong-Convictions-Emmett-Strong-Westerns-1-by-G-P-Hutchinson.pdf
    • http://loaminoo.linkpc.net/8094094091096096/The-Roy-Strong-Diaries-1967-1987-by-Roy-C-Strong.pdf
    • http://loaminoo.linkpc.net/3097092090099096/Mad-Girl-The-Chronicles-of-Anna-Monroe-1-by-A-A-Dark.pdf
    • http://loaminoo.linkpc.net/8099096095090/The-Heart-s-Longing-Briarcrest-Chronicles-3-by-Anna-Furtado.pdf
    • http://loaminoo.linkpc.net/1097098095097099/Close-Liaisons-The-Krinar-Chronicles-1-by-Anna-Zaires.pdf
    • http://loaminoo.linkpc.net/4093094096093099/Close-Obsession-The-Krinar-Chronicles-2-by-Anna-Zaires.pdf
    • http://loaminoo.linkpc.net/3096090092091096/Alone-in-the-Crowd-The-Chronicles-of-Anna-Foster-3-by-Patrick-Stutzman.pdf
    • http://loaminoo.linkpc.net/4092098090091092/Cursed-Legacy-Aeterna-Chronicles-1-by-Anna-K-Lane.pdf
    • http://loaminoo.linkpc.net/2096092097094097/Close-Obsession-The-Krinar-Chronicles-2-by-Anna-Zaires.pdf
    • http://loaminoo.linkpc.net/1090096094098096092/Knowledge-Encyclopedia-with-Prof-Hein-Stein-by-Hein-Stein.pdf