Malicious PDF — malware analysis report

Static analysis result for SHA-256 1972b69e01935827…

MALICIOUS

PDF

18.3 KB Created: 2019-05-03 05:59:44 +01:00 Authoring application: mPDF 5.7
MD5: ad1bceecc54dfb9aa45773dc2b0288ea SHA-1: 5440618ddcde3785c691f71b7640c97ecfb076a8 SHA-256: 1972b69e0193582765ba5fd8abd78a39234e3c71b233d95da41c75a656a4a3df
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, masquerading as book titles, which is indicative of a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious. The primary attack pattern observed is the use of a link farm to direct users to potentially malicious content, likely as a form of phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095099090098099/The-Hogwarts-Collection-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/3099098099/Hogwarts-An-Incomplete-and-Unreliable-Guide-Pottermore-Presents-3-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/2093091095090099/Hogwarts-An-Incomplete-and-Unreliable-Guide-Pottermore-Presents-3-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/3099098094/Short-Stories-from-Hogwarts-of-Heroism-Hardship-and-Dangerous-Hobbies-Pottermore-Presents-1-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/1097095095095096/Short-Stories-from-Hogwarts-of-Heroism-Hardship-and-Dangerous-Hobbies-Pottermore-Presents-1-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/2096090094091092/Short-Stories-from-Hogwarts-of-Power-Politics-and-Pesky-Poltergeists-Pottermore-Presents-2-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/6093090091093098/Harry-Potter-and-the-Philosopher-s-Stone-4-Books-Bundle-Collection-By-J-K-Rowling-With-Gift-Journal-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/3097090092094094/Harry-Potter-Audio-Collection-Harry-Potter-1-7-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/2091095099097090/The-Harry-Potter-Collection-Harry-Potter-1-4-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/5092098094090097/The-Deathly-Hallows-Lectures-The-Hogwarts-Professor-Explains-the-Final-Harry-Potter-Adventure-by-John-Granger.pdf
    • http://loaminoo.linkpc.net/7099091096092097/What-s-Your-Story-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/7099091097092096/All-about-J-K-Rowling-by-Shaun-McCarthy.pdf
    • http://loaminoo.linkpc.net/7099091097093094/J-K-Rowling-by-Bryan-Pezzi.pdf
    • http://loaminoo.linkpc.net/7099091097093097/--Vol-1-of-2-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/7099091096093090/J-K-Rowling-by-Sarah-Tieck.pdf
    • http://loaminoo.linkpc.net/5095094094097/The-Casual-Vacancy-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/7090094094098092/J-K-Rowling-A-Biography-by-Connie-Ann-Kirk.pdf
    • http://loaminoo.linkpc.net/7090094095091090/The-J-K-Rowling-Encyclopedia-by-Connie-Ann-Kirk.pdf
    • http://loaminoo.linkpc.net/1090094092093098/J-K-Rowling---A-Biography-by-Sean-Smith.pdf
    • http://loaminoo.linkpc.net/3092094095097/The-Tales-of-Beedle-the-Bard-by-J-K-Rowling.pdf