Malicious PDF — malware analysis report

Static analysis result for SHA-256 17c6845e3cead494…

MALICIOUS

PDF

22.4 KB Created: 2019-04-30 18:06:10 +01:00 Authoring application: mPDF 5.7
MD5: f4f3b49fe1a7d2efb2ff0a14c1996d73 SHA-1: a8d5b76d12255e2ef509537d098693e6995a5039 SHA-256: 17c6845e3cead494fe8d93e43aacffcf2b9054f19a85a9064d7e1554a8cf0768
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier also flagged this PDF as malicious. The URLs are hosted on a dynamic DNS domain, suggesting a transient infrastructure. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8095090096090091/A-Brush-With-Nature-The-Gere-Collection-of-Landscape-Oil-Sketches-Revised-Edition-by-Christopher-Riopelle.pdf
    • http://loaminoo.linkpc.net/8095090096090090/Forests-Rocks-Torrents-Norwegian-and-Swiss-Landscape-Paintings-from-the-Lunde-Collection-by-Christopher-Riopelle.pdf
    • http://loaminoo.linkpc.net/5097097099092097/Landscape-in-the-Longue-Dur-e-A-History-and-Theory-of-Pebbles-in-a-Pebbled-Heathland-Landscape-by-Christopher-Tilley.pdf
    • http://loaminoo.linkpc.net/8095090097091097/Tim-Gardner-New-Works-by-Christopher-Riopelle.pdf
    • http://loaminoo.linkpc.net/8095090095099093/Paintings-by-Peder-Balke-by-Christopher-Riopelle.pdf
    • http://loaminoo.linkpc.net/3093092092090093/Caesar-s-Commentaries-the-Complete-Gallic-Wars-Revised-Revised-Edition-by-Gaius-Julius-Caesar.pdf
    • http://loaminoo.linkpc.net/1090091097090099091/A-Primer-for-Local-Historical-Societies-Revised-and-Expanded-from-the-First-Edition-by-Dorothy-Weyer-Creigh-Revised-and-Expanded-from-the-First-Edition-by-Dorothy-Weyer-Creigh-by-Laurence-R-Pizer.pdf
    • http://loaminoo.linkpc.net/1091099090096093091/Psychological-Sketches-A-Collection-of-Short-Fiction-by-Lucette-Desvignes.pdf
    • http://loaminoo.linkpc.net/5091090095098090/Across-The-Mutual-Landscape-by-Christopher-Gilbert.pdf
    • http://loaminoo.linkpc.net/1095092096097/Nature-and-Culture-American-Landscape-and-Painting-1825-1875-by-Barbara-Novak.pdf
    • http://loaminoo.linkpc.net/5090096095091094/The-Conquest-of-Nature-Water-Landscape-and-the-Making-of-Modern-Germany-by-David-Blackbourn.pdf
    • http://loaminoo.linkpc.net/4099094097095091/The-Guide-to-Walden-Pond-An-Exploration-of-the-History-Nature-Landscape-and-Literature-of-One-of-America-s-Most-Iconic-Places-by-Robert-M-Thorson.pdf
    • http://loaminoo.linkpc.net/6090092090095/The-School-Reform-Landscape-Fraud-Myth-and-Lies-by-Christopher-H-Tienken.pdf
    • http://loaminoo.linkpc.net/1091097097093096092/Leadership-Virtuosity-New-and-Revised-Edition-by-Lee-Thayer.pdf
    • http://loaminoo.linkpc.net/1091097097093095098/Leadership-Virtuosity-New-and-Revised-Edition-by-Lee-Thayer.pdf
    • http://loaminoo.linkpc.net/8094099095091096/The-Crucible-Revised-Edition-by-Arthur-Miller.pdf
    • http://loaminoo.linkpc.net/1091099091096092093/Acting-for-the-Camera-Revised-Edition-by-Tony-Barr.pdf
    • http://loaminoo.linkpc.net/5097090092092/Gun-Control-amp-The-Second-Amendment-2nd-Edition-Revised-amp-Expanded-by-Byron-Goines.pdf
    • http://loaminoo.linkpc.net/8092091090094092/Jack-and-the-Journey-Through-Time-Revised-Edition-by-Manook-Sarkisyan.pdf
    • http://loaminoo.linkpc.net/7098090099090096/A-Study-of-Vermeer-Revised-and-Enlarged-edition-by-Edward-Snow.pdf