Malicious PDF — malware analysis report

Static analysis result for SHA-256 3246eceb8ff96572…

MALICIOUS

PDF

16.6 KB Created: 2019-04-30 04:07:49 +01:00 Authoring application: mPDF 5.7
MD5: b000ffc7816f007ba5d3da64c75443b4 SHA-1: 5e869a4bc2ec67b65588b9e8bc8565cb29a3c423 SHA-256: 3246eceb8ff9657299c30d515d674a32b11cc7511c1bf55501b6f4ab75ee75a4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF was flagged by a machine learning classifier and contains a large number of embedded URLs pointing to external PDF documents. The heuristic PDF_SEO_LINK_FARM indicates a link farm strategy, suggesting the primary goal is to drive traffic to these external resources. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5094098096090090/I-m-With-Fatty-Losing-Fifty-Pounds-in-Fifty-Miserable-Weeks-by-Edward-Ugel.pdf
    • http://loaminoo.linkpc.net/7099093094095/Fifty-Shades-Duo-Fifty-Shades-Darker-Fifty-Shades-Freed-Fifty-Shades-2-3-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/3093091094090095/Fifty-two-Weeks-of-Submission-by-J-R-James.pdf
    • http://loaminoo.linkpc.net/1097094092090094/Fifty-Shades-of-Naughty-1-of-the-Fifty-Shades-of-Naughty-Trilogy-by-Edward-Naughty.pdf
    • http://loaminoo.linkpc.net/1097091091092090/Meet-Fifty-Shades-Continued---Fifty-Shades-of-Grey-by-G-E-Griffin.pdf
    • http://loaminoo.linkpc.net/6090099093098/What-Can-Chief-Executives-Learn-from-Standup-Comedians-Fifty-Essential-Skills-Top-Performers-Perfect-by-Roger-Edward-Jones.pdf
    • http://loaminoo.linkpc.net/5097095098095099/Grey---Fifty-Shades-of-Grey-von-Christian-selbst-erz-hlt-Fifty-Shades-4-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/3093092099096093/Fifty-Shades-Freed-Fifty-Shades-3-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/2094090094099094/Fifty-Shades-Darker-Fifty-Shades-2-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/8099091094098099/Hugo-Von-Hofmannsthal-s-Der-Schwierige-a-Fifty-Year-Theater-History-Hugo-Von-Hofmannsthal-s-Der-Schwierige-a-Fifty-Year-Theater-History-by-Douglas-A-Joyce.pdf
    • http://loaminoo.linkpc.net/3092099098094091/A-Pirate-Looks-at-Fifty-by-Jimmy-Buffett.pdf
    • http://loaminoo.linkpc.net/5093099090092096/Fifty-Grand-by-Adrian-McKinty.pdf
    • http://loaminoo.linkpc.net/1091098096099090/The-Fifty-List-by-Darlene-Hesley.pdf
    • http://loaminoo.linkpc.net/1090091094098094097/Fifty-Shades-of-Grey-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/2097093091098090/Fifty-First-Times-by-Julie-Cross.pdf
    • http://loaminoo.linkpc.net/1090092091/Grey-Fifty-Shades-4-by-E-L-James.pdf
    • http://loaminoo.linkpc.net/3090096092096093/Fifty-Shades-of-BDSM-by-Sky-Corgan.pdf
    • http://loaminoo.linkpc.net/3093092092097090/Fifty-One-Tales-by-Lord-Dunsany.pdf
    • http://loaminoo.linkpc.net/8097094098092097/The-Fifty-Minute-Hour-by-Robert-Lindner.pdf
    • http://loaminoo.linkpc.net/9099099093093092/Earwitness-Fifty-Characters-by-Elias-Canetti.pdf
    • http://loaminoo.linkpc.net/2094090094099094/Fifty-Shades-Da