Malicious PDF — malware analysis report

Static analysis result for SHA-256 166162c4fa4db5ff…

MALICIOUS

PDF

18.1 KB Created: 2019-05-01 18:35:27 +01:00 Authoring application: mPDF 5.7
MD5: 7a14369b8b0c719e136945c97becf8d6 SHA-1: 8a3229bcfdb9bb83c1fa071b03e3b3669c4d2a86 SHA-256: 166162c4fa4db5ffc430dfcdc1e8c3b0c4331833c61ba57ad199b9206cf10c7e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the same dynamic DNS domain. This behavior is indicative of a link farm or a method to distribute further malicious content. The ML classifier also flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5090092090097095/Christmas-is-Coming-with-Ruth-J-Morehead-s-Holly-Babes-by-Ruth-J-Morehead.pdf
    • http://loaminoo.linkpc.net/3097094096092093/One-Christmas-Night-Highland-Christmas-A-Wife-For-Christmas-Ian-s-Gift-by-Ruth-Ryan-Langan.pdf
    • http://loaminoo.linkpc.net/2095098099099095/Snippets-of-Ruth-Ponderings-from-a-Word-Watcher-by-Ruth-Wajnryb.pdf
    • http://loaminoo.linkpc.net/3090092095090090/Ruth-s-Bonded-Ruth-amp-Gron-1-by-V-C-Lancaster.pdf
    • http://loaminoo.linkpc.net/1094096095097/The-Year-of-the-Christmas-Dragon-by-Ruth-Sawyer.pdf
    • http://loaminoo.linkpc.net/4098090097095098/Ruth-s-First-Christmas-Tree-by-Elly-Griffiths.pdf
    • http://loaminoo.linkpc.net/7096096091095095/It-s-a-Woman-s-World-A-Bouyant-Guide-to-Easier-More-Enjoyable-Living-Ruth-Stout-Book-4-by-Ruth-Stout.pdf
    • http://loaminoo.linkpc.net/3090093099095093/Stewart-and-Leah-Home-for-Christmas-by-Ruth-Madison.pdf
    • http://loaminoo.linkpc.net/3098094096099098/24-1-Christmas-Tales-Butterfly-Adventures-in-Santa-s-Secret-City-by-Alexander-Ruth.pdf
    • http://loaminoo.linkpc.net/2097094097090099/Ruth-Fielding-On-Cliff-Island-Ruth-Fielding-6-by-Alice-B-Emerson.pdf
    • http://loaminoo.linkpc.net/2097094092092094/Ruth-Fielding-at-Lighthouse-Point-Ruth-Fielding-4-by-Alice-B-Emerson.pdf
    • http://loaminoo.linkpc.net/2097096094091097/Ruth-Fielding-in-the-Saddle-Ruth-Fielding-12-by-Alice-B-Emerson.pdf
    • http://loaminoo.linkpc.net/2097096096093099/Ruth-Fielding-in-the-Red-Cross-Ruth-Fielding-13-by-Alice-B-Emerson.pdf
    • http://loaminoo.linkpc.net/3093097094091092/Ruth-Longknife-s-First-Christmas-Kris-Longknife-14-1-by-Mike-Shepherd.pdf
    • http://loaminoo.linkpc.net/2098097097097093/Ruth-Rendell-Omnibus-II-quot-From-Doon-with-Death-quot-quot-Some-Lie-and-Some-Die-quot-quot-Shake-Hands-for-Ever-quot-quot-A-Sleeping-Life-quot-by-Ruth-Rendell.pdf
    • http://loaminoo.linkpc.net/1091099096098097096/Superstar-Babes-Bindi-Babes-4-by-Narinder-Dhami.pdf
    • http://loaminoo.linkpc.net/2098097097097095/Ruth-Rendell-Omnibus-by-Ruth-Rendell.pdf
    • http://loaminoo.linkpc.net/1093092093097095/This-Christmas-Christmas-in-New-York-1-Holly-Point-NY-1-by-Jeannie-Moon.pdf
    • http://loaminoo.linkpc.net/3093096097094091/Apocalypse-Babes-The-Complete-Series-Apocalypse-Babes-1-6-by-Bella-Street.pdf
    • http://loaminoo.linkpc.net/3095094094095092/Get-Your-Sh-t-Together-by-Ruth-Field.pdf