Malicious PDF — malware analysis report

Static analysis result for SHA-256 34eb767c83ba2f79…

MALICIOUS

PDF

14.9 KB Created: 2019-04-30 04:29:45 +01:00 Authoring application: mPDF 5.7
MD5: 9b6948603ffc67a880dc9b261c9224e2 SHA-1: 6cbf36dcb22355410131551283fe225d2aca452e SHA-256: 34eb767c83ba2f79c9142a84e1dd3027ff3cd501cb2c435d91a20095e5982edb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic identified this pattern. The document body, though heavily obfuscated, contains these URLs, suggesting the primary purpose is to redirect users to a large collection of other documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3094098094095/Shadow-amp-Claw-The-Book-of-the-New-Sun-1-2-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/5097098098096/Shadow-and-Claw-The-Book-of-the-New-Sun-1-2-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/3093090095099095/The-Shadow-of-the-Torturer-The-Book-of-the-New-Sun-1-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/2094099099095/The-Sword-of-the-Lictor-The-Book-of-the-New-Sun-3-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/3098091099098/Sword-amp-Citadel-The-Book-of-the-New-Sun-3-4-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/3097097094091095/Sword-amp-Citadel-The-Book-of-the-New-Sun-3-4-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/1097092097098096/On-Blue-s-Waters-The-Book-of-the-Short-Sun-1-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/1094091095093099/Return-to-the-Whorl-The-Book-of-the-Short-Sun-3-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/5094096097099/Exodus-from-the-Long-Sun-The-Book-of-the-Long-Sun-4-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/1090092095090097/Litany-of-the-Long-Sun-The-Book-of-the-Long-Sun-1-2-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/2096090092099/The-Land-Across-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/1093096098096097/Peace-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/8098090099093099/The-Hero-As-Werwolf-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/2097094096097/The-Fifth-Head-of-Cerberus-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/5094092095095/An-Evil-Guest-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/4096098091099097/Soldier-of-Arete-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/2093093090/Avatar-The-Last-Airbender-Smoke-and-Shadow-Part-2-Smoke-and-Shadow-2-by-Gene-Luen-Yang.pdf
    • http://loaminoo.linkpc.net/9098094092091094/The-Crime-Gene-The-Crime-Gene-Series-Book-1-by-Joyce-Nance.pdf
    • http://loaminoo.linkpc.net/2095090095094/The-Island-of-Dr-Death-and-Other-Stories-and-Other-Stories-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/1094093092093091/The-Wizard-The-Wizard-Knight-2-by-Gene-Wolfe.pdf