Malicious PDF — malware analysis report

Static analysis result for SHA-256 4569caee77f8515f…

MALICIOUS

PDF

21.4 KB Created: 2019-04-30 04:09:10 +01:00 Authoring application: mPDF 5.7
MD5: 9f988a6f10bf314e77e13d11eb295a30 SHA-1: ac54bf8ebdf6ae46f36a45148be86ba7b75d0215 SHA-256: 4569caee77f8515f043cb2bb7daa090c923d1095e7f271826ea84625b3c91739
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external websites. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. The embedded links likely serve as a lure to direct users to potentially malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7099094097095/How-to-Betray-a-Dragon-s-Hero-How-to-Train-Your-Dragon-11-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/2099093093093092/A-Hero-s-Guide-to-Deadly-Dragons-How-to-Train-Your-Dragon-6-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/4097095096091/A-Hero-s-Guide-to-Deadly-Dragons-How-to-Train-Your-Dragon-6-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/9091094091092098/How-to-Train-Your-Dragon-How-to-Train-Your-Dragon-1-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/3095098091098/How-to-Train-Your-Dragon-How-to-Train-Your-Dragon-1-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/4092095097092097/How-to-Train-Your-Dragon-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/1091093096093092095/M-rderische-Drachenfl-che-How-to-Train-Your-Dragon-4-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/7090096097091095/N-in-koulutat-lohik-rmeesi-How-to-Train-Your-Dragon-1-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/8091093099093/The-Day-of-the-Dreader-How-to-Train-Your-Dragon-World-Book-Day-2012-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/2099093094092098/How-to-Cheat-a-Dragon-s-Curse-Hiccup-Horrendous-Haddock-III-4-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/3097094092096097/G-A-Aiken-Dragon-Bundle-The-Dragon-Who-Loved-Me-What-a-Dragon-Should-Know-Last-Dragon-Standing-amp-How-to-Drive-a-Dragon-Crazy-The-Dragon-Kin-3-6-by-G-A-Aiken.pdf
    • http://loaminoo.linkpc.net/4099093097095099/Dragon-Prince-Series-Including-Melanie-Rawn-Dragon-Prince-Sunrunner-s-Fire-the-Star-Scroll-Sunrunner-High-Prince-Stronghold-Novel-the-Dragon-Token-Skybowl-Dragon-Prince-and-Dragon-Star-Trilogies-Diarmadhi-Merida-Dragon-Prince-Isulk-im-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/2093094098099091/Call-of-the-Dragon-a-Dragon-Fantasy-Adventure-Dragon-Riders-of-Elantia-Book-1-by-Jessica-Drake.pdf
    • http://loaminoo.linkpc.net/9099094098093096/Drachenz-hmen-leicht-gemacht-1-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/3096095090091093/That-Rabbit-Belongs-to-Emily-Brown-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/9099094098094092/Drachenz-hmen-leicht-gemacht-5-Brandgef-hrliche-Feuerspeier-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/9094091094094096/Drachenz-hmen-leicht-gemacht-3-Strenggeheimes-Drachenfl-stern-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/9094091093097093/Drachenz-hmen-leicht-gemacht-2-Wilde-Piraten-voraus-by-Cressida-Cowell.pdf
    • http://loaminoo.linkpc.net/5094097091090/A-Hero-for-the-Empire-The-Dragon-s-Bidding-1-by-Christina-Westcott.pdf
    • http://loaminoo.linkpc.net/8097095092096091/G-A-Aiken-Bundle-The-Dragon-Who-Loved-Me-What-a-Dragon-Should-Know-amp-Last-Dragon-Standing-by-G-A-Aiken.pdf
    • http://loaminoo.linkpc.net