Malicious PDF — malware analysis report

Static analysis result for SHA-256 0cbfc13962bc5309…

MALICIOUS

PDF

20.7 KB Created: 2019-04-30 03:30:04 +01:00 Authoring application: mPDF 5.7
MD5: 1b16af70c16a2be4a403c08bc5121ae5 SHA-1: fd25ae7b711a2c4e79525772eb664d282b845409 SHA-256: 0cbfc13962bc5309842308f57e152d75901b2e57931943056ffb8596c0ff940e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous URLs suggests an attempt to redirect users to potentially malicious content or for SEO manipulation. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3091090097099096/Chasing-the-Dragon-Deception-Duet-1-by-T-K-Leigh.pdf
    • http://loaminoo.linkpc.net/1090099097091095/Chasing-The-Dragon-by-Laura-Moe.pdf
    • http://loaminoo.linkpc.net/9098090094092/Chasing-the-Dragon-by-Nicholas-Kaufmann.pdf
    • http://loaminoo.linkpc.net/2098095098092099/Chasing-the-Dragon-Lost-Innocence-1-by-T-R-Graves.pdf
    • http://loaminoo.linkpc.net/1090099090098093092/Dragon-Deception-Supernatural-Consultant-2-by-Mell-Eight.pdf
    • http://loaminoo.linkpc.net/8098097092096/Tracker-and-the-Spy-Dragon-Horse-War-2-by-D-Jackson-Leigh.pdf
    • http://loaminoo.linkpc.net/5095095093094090/Sugar-Dragon-A-Kinship-Cove-Fun-amp-Flirty-Romance-by-Ellis-Leigh.pdf
    • http://loaminoo.linkpc.net/3097094092096097/G-A-Aiken-Dragon-Bundle-The-Dragon-Who-Loved-Me-What-a-Dragon-Should-Know-Last-Dragon-Standing-amp-How-to-Drive-a-Dragon-Crazy-The-Dragon-Kin-3-6-by-G-A-Aiken.pdf
    • http://loaminoo.linkpc.net/4099093097095099/Dragon-Prince-Series-Including-Melanie-Rawn-Dragon-Prince-Sunrunner-s-Fire-the-Star-Scroll-Sunrunner-High-Prince-Stronghold-Novel-the-Dragon-Token-Skybowl-Dragon-Prince-and-Dragon-Star-Trilogies-Diarmadhi-Merida-Dragon-Prince-Isulk-im-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/2095091095097096/Chasing-Fireflies-The-Chasing-Series-1-by-Paige-P-Horne.pdf
    • http://loaminoo.linkpc.net/6093094094099090/Babar-Story-Book-To-Duet-Or-Not-to-Duet-Babar-Series-by-Laurent-de-Brunhoff.pdf
    • http://loaminoo.linkpc.net/1092090096097098/Deception-s-Pawn-Deception-s-Princess-2-by-Esther-M-Friesner.pdf
    • http://loaminoo.linkpc.net/2093094098099091/Call-of-the-Dragon-a-Dragon-Fantasy-Adventure-Dragon-Riders-of-Elantia-Book-1-by-Jessica-Drake.pdf
    • http://loaminoo.linkpc.net/1097092098098091/Accidental-Leigh-Literal-Leigh-Romance-Diaries-1-by-Melanie-James.pdf
    • http://loaminoo.linkpc.net/3099090098092098/Hopeful-Leigh-Literal-Leigh-Romance-Diaries-3-by-Melanie-James.pdf
    • http://loaminoo.linkpc.net/1091095097093092/Chasing-the-Valley-Chasing-the-Valley-1-by-Skye-Melki-Wegner.pdf
    • http://loaminoo.linkpc.net/3099094095090094/Deception-Deception-1-by-K-A-Robinson.pdf
    • http://loaminoo.linkpc.net/2095093094097097/The-Trident-Deception-Trident-Deception-1-by-Rick-Campbell.pdf
    • http://loaminoo.linkpc.net/3096095091094098/Royal-Deception-Royal-Deception-1-by-Denae-Christine.pdf
    • http://loaminoo.linkpc.net/8097095092096091/G-A-Aiken-Bundle-The-Dragon-Who-Loved-Me-What-a-Dragon-Should-Know-amp-Last-Dragon-Standing-by-G-A-Aiken.pdf