Malicious PDF — malware analysis report

Static analysis result for SHA-256 2bc89f82bb4dbbd6…

MALICIOUS

PDF

16.3 KB Created: 2019-04-30 03:15:56 +01:00 Authoring application: mPDF 5.7
MD5: a43a2c9a972e11890c7682fc7e8936f5 SHA-1: e20d849062a84fe0c0827d4346d912e7134d74a9 SHA-256: 2bc89f82bb4dbbd6a03c5950259dbaab62ccb5dec11bc66c8340f2d3ac0bab89
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic identified the link farm. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2096095091097095/Transcendence-Aurora-Rising-Book-Three-Aurora-Rhapsody-3-by-G-S-Jennsen.pdf
    • http://loaminoo.linkpc.net/2098092099095090/Transcendence-Aurora-Rising-Book-Three-Aurora-Rhapsody-3-by-G-S-Jennsen.pdf
    • http://loaminoo.linkpc.net/2091094096094093/Vertigo-Aurora-Rhapsody-2-by-G-S-Jennsen.pdf
    • http://loaminoo.linkpc.net/3098097093090091/Starshine-Aurora-Rising-1-by-G-S-Jennsen.pdf
    • http://loaminoo.linkpc.net/2094095096094092/Aurora-Rising-The-Complete-Collection-by-G-S-Jennsen.pdf
    • http://loaminoo.linkpc.net/1091094090097098091/Dissonance-Aurora-Renegades-2-by-G-S-Jennsen.pdf
    • http://loaminoo.linkpc.net/6099094094095094/On-the-Aurora-Borealis-and-the-Aurora-Australis-by-Joseph-Lovering.pdf
    • http://loaminoo.linkpc.net/9092092095090/Aurora-Meridian-Aurora-3-by-Amanda-Bridgeman.pdf
    • http://loaminoo.linkpc.net/6097093094092/The-Aurora-Teagarden-Mysteries-Omnibus-1-Aurora-Teagarden-1-4-by-Charlaine-Harris.pdf
    • http://loaminoo.linkpc.net/3098090095091092/Become-the-Woman-of-Your-Dreams-Interactive-Gender-Transformation-Feminization-Erotica-Aurora-Sparks-Interactive-Erotica-1-by-Aurora-Sparks.pdf
    • http://loaminoo.linkpc.net/1091099090099095094/Northern-Lights-A-Kid-s-Book-About-Aurora-Borealis-by-Nicholas-Eliott.pdf
    • http://loaminoo.linkpc.net/4095093099096095/Drawn-Into-Love-Fluke-My-Life-Book-4-by-Aurora-Rose-Reynolds.pdf
    • http://loaminoo.linkpc.net/1092094096096091/Aurora-Conspiracy-The-Story-Didn-t-End-with-a-Crash-the-Epic-Journey-Began-Book-1-by-Ginger-Gelsheimer.pdf
    • http://loaminoo.linkpc.net/3092097093094092/Willing-Captive-by-Belle-Aurora.pdf
    • http://loaminoo.linkpc.net/2099099094095090/Aurora-s-Consort-by-pesterme2.pdf
    • http://loaminoo.linkpc.net/4099096098099090/Aurora-by-Mark-Robson.pdf
    • http://loaminoo.linkpc.net/1096095091/Until-Jax-Until-Him-1-by-Aurora-Rose-Reynolds.pdf
    • http://loaminoo.linkpc.net/1098091097090094/The-Aurora-by-Michelle-Woods.pdf
    • http://loaminoo.linkpc.net/6096095098090093/Aurora-Terminus-by-S-E-Fanetti.pdf
    • http://loaminoo.linkpc.net/1091092096094098092/Willing-Captive-by-Belle-Aurora.pdf
    • http://loaminoo.linkpc.net/3