Malicious PDF — malware analysis report

Static analysis result for SHA-256 587034a42ca276ee…

MALICIOUS

PDF

17.8 KB Created: 2019-05-07 09:47:05 +01:00 Authoring application: mPDF 5.7
MD5: 994ef24c494882bead750b1ea22f7b82 SHA-1: a9b5a8da910896692cb2eb25ead7f4896fd0d2f3 SHA-256: 587034a42ca276eec9260193e19fc7f2c2e1f8eff7c4567cb4922579555db313
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. These URLs point to what appear to be book titles, suggesting a lure to download or view external content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the suspicious nature of the embedded links. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5097091099092095/To-the-Last-Man-A-Novel-of-the-First-World-War-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/6097093093094/Gone-for-Soldiers-A-Novel-of-the-Mexican-War-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/7091097099091/No-Less-Than-Victory-World-War-II-1939-1945-3-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/7090097092093/The-Steel-Wave-World-War-II-1939-1945-2-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/1092096099092096/The-Glorious-Cause-American-Revolutionary-War-1770-1783-2-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/7092097094096/The-Final-Storm-World-War-II-1939-1945-4-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/8091096096098/Three-Novels-of-World-War-II-The-Rising-Tide-The-Steel-Wave-No-Less-Than-Victory-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/6096097094097/A-Chain-of-Thunder-Civil-War-1861-1865-Western-Theater-2-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/9090093092098099/Rise-to-Rebellion-A-Novel-of-the-American-Revolution-The-American-Revolutionary-War-by-Jeff-Shaara.pdf
    • http://loaminoo.linkpc.net/5099098094093097/Fat-Loss-Strategy-Little-Dirty-Secrets-and-Weird-Tricks-to-Massive-Fat-Loss-and-Sexy-Drooling-Body-Lose-the-Fat-Take-Control-of-Your-Body-Look-Like-Descendant-of-the-Roman-Gods-by-Jeff-Sandorf.pdf
    • http://loaminoo.linkpc.net/5091095090094094/The-Generals-by-Per-Wahl-.pdf
    • http://loaminoo.linkpc.net/4098098092098097/Gods-of-Fire-and-Thunder-Book-of-the-Gods-5-by-Fred-Saberhagen.pdf
    • http://loaminoo.linkpc.net/4094094093097090/Two-Generals-by-Scott-Chantler.pdf
    • http://loaminoo.linkpc.net/3091094098098093/In-the-Shadow-of-the-Gods-Bound-Gods-1-by-Rachel-Dunne.pdf
    • http://loaminoo.linkpc.net/3091099098096092/Oh-My-Gods-A-Look-It-Up-Guide-to-the-Gods-of-Mythology-by-Megan-E-Bryant.pdf
    • http://loaminoo.linkpc.net/2099095098097094/Heart-of-the-Gods-Servant-of-the-Gods-2-by-Valerie-Douglas.pdf
    • http://loaminoo.linkpc.net/4096091092096097/The-Killer-Angels-The-Civil-War-Trilogy-2-by-Michael-Shaara.pdf
    • http://loaminoo.linkpc.net/2095094094094092/Lincoln-and-His-Generals-by-T-Harry-Williams.pdf
    • http://loaminoo.linkpc.net/8092096096099/God-s-Generals-Why-They-Succeeded-and-Why-Some-Fail-by-Roberts-Liardon.pdf
    • http://loaminoo.linkpc.net/2093095096099093/Grant-The-Generals-Series-by-Mitchell-A-Yockelson.pdf
    • http://loaminoo.linkpc.net/9090093092098099/Rise-to-Rebellion-A-Novel-of-the-American-Revolution-The-American-Revolut