Malicious PDF — malware analysis report

Static analysis result for SHA-256 2663e862bc081c6c…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 04:23:14 +01:00 Authoring application: mPDF 5.7
MD5: 0a0b145a173e669081a32c4d797cadb8 SHA-1: c48ca86b8b4389571966acce4db53a250babf138 SHA-256: 2663e862bc081c6c898c98883d758348507b69056575b2c8244f53a2a61aae7a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs appear to point to book titles, the sheer volume and the ML_NYX_PDF_MALICIOUS firing suggest a malicious intent, likely to manipulate search engine results or redirect users to malicious sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3090097094094090/The-Wiz-Biz-Wiz-1-2-by-Rick-Cook.pdf
    • http://loaminoo.linkpc.net/9091096092096094/The-Wizardry-Cursed-Wiz-3-by-Rick-Cook.pdf
    • http://loaminoo.linkpc.net/1091098097099096095/Im-Netz-des-Wachtturms---ein-Vater-k-mpft-um-seine-Kinder-Will-Cook-und-die-Wachtturmgesellschaft-by-Will-Cook.pdf
    • http://loaminoo.linkpc.net/2096097096092093/How-to-Cook-Without-a-Book-Recipes-and-Techniques-Every-Cook-Should-Know-by-Heart-by-Pam-Anderson.pdf
    • http://loaminoo.linkpc.net/3091091091090094/How-to-Cook-Everything-Fast-A-Better-Way-to-Cook-Great-Food-by-Mark-Bittman.pdf
    • http://loaminoo.linkpc.net/4093098095097092/The-Journals-of-Captain-Cook-by-James-Cook.pdf
    • http://loaminoo.linkpc.net/1090091091092094098/Rick-Steves-Mona-Winks-Self-Guided-Tours-of-Europe-s-Top-Museums-by-Rick-Steves.pdf
    • http://loaminoo.linkpc.net/3090098092099091/What-to-Cook-and-How-to-Cook-It-by-Jane-Hornby.pdf
    • http://loaminoo.linkpc.net/4097094090094099/Rick-Steves-Northern-European-Cruise-Ports-by-Rick-Steves.pdf
    • http://loaminoo.linkpc.net/5095099098091097/Uncanny-X-Force-by-Rick-Remender-Omnibus-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/7096097093094098/Rick-Steves-Florence-amp-Tuscany-2007-by-Rick-Steves.pdf
    • http://loaminoo.linkpc.net/7093094093097093/Rick-Steves-Greece-Athens-amp-the-Peloponnese-by-Rick-Steves.pdf
    • http://loaminoo.linkpc.net/1091096091090096093/Rick-Steves-Great-Britain-2007-by-Rick-Steves.pdf
    • http://loaminoo.linkpc.net/2096091091098095/Tragically-I-Was-an-Only-Twin-The-Complete-Peter-Cook-by-Peter-Cook.pdf
    • http://loaminoo.linkpc.net/1094092092090093/Rick-Mears-Thanks-The-Story-of-Rick-Mears-and-the-Mears-Gang-by-Gordon-Kirby.pdf
    • http://loaminoo.linkpc.net/7097090091095097/The-Voyages-of-Captain-James-Cook-The-Illustrated-Accounts-of-Three-Epic-Pacific-Voyages-by-James-Cook.pdf
    • http://loaminoo.linkpc.net/5095099098091095/Punisher-by-Rick-Remender-Omnibus-by-Rick-Remender.pdf
    • http://loaminoo.linkpc.net/1090090096095093/Rick-Steves-Paris-2007-by-Rick-Steves.pdf
    • http://loaminoo.linkpc.net/1091096091091096092/Rick-Steves-Venice-2007-by-Rick-Steves.pdf
    • http://loaminoo.linkpc.net/1091095093095095095/The-Rick-Strachan-Guitar-Collection-by-Rick-Strachan.pdf
    • http://loaminoo.linkpc.net/4093098095097092/The-Journals-of-Captain-Cook-by-James-