Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b35e62e8031d3d6…

MALICIOUS

PDF

22.4 KB Created: 2019-05-02 19:21:29 +01:00 Authoring application: mPDF 5.7
MD5: 25a1fe202f4b47936d9fadbd07e78190 SHA-1: 8487fbe41cc00bfaa5f2bf4b8a5294c6cf9cb6ca SHA-256: 2b35e62e8031d3d6e4a804c64b4be62e00a60d05b7a5186cfa6a846b5ba20b4d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a link farm hosted on a dynamic DNS domain, likely as a precursor to a more direct attack or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8095096095090/Epiphany-True-Stories-of-Sudden-Insight-to-Inspire-Encourage-and-Transform-by-Elise-Ballard.pdf
    • http://loaminoo.linkpc.net/3096093092092093/A-Taste-of-Hot-Apple-Cider-Stories-to-Encourage-and-Inspire-by-N-J-Lindquist.pdf
    • http://loaminoo.linkpc.net/7091098098090098/Please-Help-Me-Lift-Something-Heavy-Thank-You-True-Stories-to-Amuse-and-Inspire-You-and-Maybe-Bring-a-Joyous-Tear-or-Two-by-Rick-Gelinas.pdf
    • http://loaminoo.linkpc.net/1096099098099098/Epiphany---THE-SILVERING-Epiphany-2-by-Sonya-Deanna-Terry.pdf
    • http://loaminoo.linkpc.net/1092095094092098/Epiphany---THE-SILVERING-Epiphany-2-by-Sonya-Deanna-Terry.pdf
    • http://loaminoo.linkpc.net/6098091098093093/True-Irish-Ghost-Stories-True-Hauntings-Paranormal-Investigator-Supernatural-Phenomena-from-the-real-stories---Annotated-Who-are-Celts-People-by-St-John-D-Seymour.pdf
    • http://loaminoo.linkpc.net/2091095090091094/Chronopolis-and-other-stories-by-J-G-Ballard.pdf
    • http://loaminoo.linkpc.net/1096094090098099/Low-Flying-Aircraft-And-Other-Stories-by-J-G-Ballard.pdf
    • http://loaminoo.linkpc.net/7095095090096/True-Crime-Stories-10-Heinous-True-Crime-Stories-Of-Sickly-Serial-Killers-Murderers-And-Sociopaths-by-Travis-S-Kennedy.pdf
    • http://loaminoo.linkpc.net/4099094098091092/Insight-Insight-1-Web-of-Hearts-and-Souls-1-by-Jamie-Magee.pdf
    • http://loaminoo.linkpc.net/2093097093098096/Chicken-Soup-for-the-Nurse-s-Soul-Second-Dose-More-Stories-to-Honor-and-Inspire-Nurses-by-Jack-Canfield.pdf
    • http://loaminoo.linkpc.net/2092094098099/Classics-How-we-can-encourage-children-to-read-them-Classics-Why-we-should-encourage-children-to-read-them-Book-2-by-Fiza-Pathan.pdf
    • http://loaminoo.linkpc.net/4091095091091094/Chicken-Soup-for-the-Sports-Fan-s-Soul-Stories-of-Insight-Inspiration-and-Laughter-in-the-World-of-Sport-by-Jack-Canfield.pdf
    • http://loaminoo.linkpc.net/7092094091097/Epiphany-Destined-4-by-Ashley-Suzanne.pdf
    • http://loaminoo.linkpc.net/1097090095099090/The-Chronicles-of-Epiphany-Jones-by-Kimberley-R-Jasper.pdf
    • http://loaminoo.linkpc.net/1097092097093093/The-Epiphany-Machine-by-David-Burr-Gerrard.pdf
    • http://loaminoo.linkpc.net/5090094095097097/You-Deserve-Love-Inspirational-Words-to-Encourage-Self-Acceptance-by-Mona-Hanna.pdf
    • http://loaminoo.linkpc.net/3090099096098098/True-Stories-by-Vincent-Zandri.pdf
    • http://loaminoo.linkpc.net/2093090094097091/The-Path-That-Gets-Brighter-A-Devotional-to-Instruct-Illustrate-and-Encourage-Kingdom-Principles-by-Deborah-Brodie.pdf
    • http://loaminoo.linkpc.net/4090094091098099/Seriously-Weird-True-Stories-02-by-Herbie-Brennan.pdf
    • http://loaminoo.linkpc.net/6098091098093093/True-Irish-Ghost-Stories-True-Hauntings-Paranormal-Investigator-Supernatural-Phenomena-from-the-real-sto