Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d83d7eabc451ecd…

MALICIOUS

PDF

16.8 KB Created: 2019-04-30 18:47:03 +01:00 Authoring application: mPDF 5.7
MD5: b03b87c45c06400bc995604dc2136032 SHA-1: 10ca6f6f69a89fd15eac93ffce27b831e3eec41e SHA-256: 0d83d7eabc451ecd03317f38b85b0608c4fa4a23fc0cf945fc7820e15fd7bc6c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. While no scripts were explicitly extracted, the heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, and the ML classifier flagged the PDF as malicious. The embedded URLs are likely part of the attack to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6093095090096/Deadly-Secrets-The-Blacklick-Valley-Mystery-Series-4-by-Donna-Cummins.pdf
    • http://loaminoo.linkpc.net/3095096094091093/Deadly-Stillwater-McRyan-Mystery-Series-2-by-Roger-Stelljes.pdf
    • http://loaminoo.linkpc.net/3091097095098098/Deadly-Secrets-Deadly-5-by-Jaycee-Clark.pdf
    • http://loaminoo.linkpc.net/4098099095091093/Sweet-Valley-High-Collection-Double-Love-Secrets-Playing-with-Fire-Sweet-Valley-High-1-3-by-Francine-Pascal.pdf
    • http://loaminoo.linkpc.net/1098098096099098/Deadly-Secret-A-Tale-from-the-Ohio-Valley-by-Sharon-A-Lavy.pdf
    • http://loaminoo.linkpc.net/1091096094090/How-a-Cowboy-Stole-Her-Heart-Larch-Valley-4-by-Donna-Alward.pdf
    • http://loaminoo.linkpc.net/1091094097091096092/Hammerhead-Six-How-Green-Berets-Waged-an-Unconventional-War-Against-the-Taliban-to-Win-in-Afghanistan-s-Deadly-Pech-Valley-by-Ronald-Fry.pdf
    • http://loaminoo.linkpc.net/4093091098096092/Wanted-Deadly-Secrets-2-by-Dee-Tenorio.pdf
    • http://loaminoo.linkpc.net/2090093096096/Convicted-Deadly-Secrets-1-by-Dee-Tenorio.pdf
    • http://loaminoo.linkpc.net/4093099094096093/Where-Secrets-Lie-by-Donna-Marie-Lanheady.pdf
    • http://loaminoo.linkpc.net/2090096099097/Suburban-Secrets-by-Donna-Birdsell.pdf
    • http://loaminoo.linkpc.net/9092095095097097/Deadly-Secrets-NY-State-Troopers-3-by-Jen-Talty.pdf
    • http://loaminoo.linkpc.net/3094091091091094/Hot-Secrets-Tall-Dark-amp-Deadly-1-by-Lisa-Renee-Jones.pdf
    • http://loaminoo.linkpc.net/1097090093096090/Dangerous-Secrets-Tall-Dark-amp-Deadly-2-by-Lisa-Renee-Jones.pdf
    • http://loaminoo.linkpc.net/2095091092094098/Beneath-the-Secrets-Part-4-Tall-Dark-amp-Deadly-3-4-by-Lisa-Renee-Jones.pdf
    • http://loaminoo.linkpc.net/2093094095097095/Stitch-Me-Deadly-An-Embroidery-Mystery-2-by-Amanda-Lee.pdf
    • http://loaminoo.linkpc.net/6094096098093094/Deadly-Aim-A-Shandra-Higheagle-Mystery-by-Paty-Jager.pdf
    • http://loaminoo.linkpc.net/5096092091098096/The-State-House-Mystery-Malorie-Darkwood-Series-A-Witch-Cozy-Mystery-by-Kayla-Rayne.pdf
    • http://loaminoo.linkpc.net/2094098098097090/Deadly-Assets-Allison-Campbell-Mystery-2-by-Wendy-Tyson.pdf
    • http://loaminoo.linkpc.net/8096092090098092/Deadly-Collection-A-Molly-Doyle-Mystery-3-by-Elaine-Flinn.pdf