Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b9374e3f5b87148…

MALICIOUS

PDF

28.9 KB Created: 2019-05-07 04:20:56 +01:00 Authoring application: mPDF 5.7
MD5: 552a60e638590da0351e8880adff16dd SHA-1: 09e7ea14d99d87597a4f1659b15c5be92e245baf SHA-256: 5b9374e3f5b87148c22b2dc5fb55dde1da6f1deb2a0af27ce215344be12a89db
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO spamming operation. While the document body is heavily obfuscated, the presence of numerous external links points towards a malicious intent to redirect users. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3091092097096/Rogue-Male-by-Geoffrey-Household.pdf
    • http://loaminoo.linkpc.net/1097095095096/Watcher-in-the-Shadows-by-Geoffrey-Household.pdf
    • http://loaminoo.linkpc.net/1097095099093094/Rogue-Male-by-Geoffrey-Household.pdf
    • http://loaminoo.linkpc.net/2098090096093098/Doom-s-Caravan-by-Geoffrey-Household.pdf
    • http://loaminoo.linkpc.net/7097093092092093/What-a-Way-to-Go-The-Guillotine-the-Pendulum-the-Thousand-Cuts-the-Spanish-Donkey-and-66-Other-Ways-of-Putting-Someone-to-Death-by-Geoffrey-Abbott.pdf
    • http://loaminoo.linkpc.net/9095097094099090/The-Cave-The-Wind-Cave-Book-1-by-Michela-Montgomery.pdf
    • http://loaminoo.linkpc.net/9098095092096094/The-Canterbury-Tales---Original-and-Modernised-Text-by-Geoffrey-Chaucer---Delphi-Classics-Illustrated-Delphi-Parts-Edition-Geoffrey-Chaucer-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/1090096098090099093/English-Grammar-for-Students-of-Spanish-The-Study-Guide-for-Those-Learning-Spanish-by-Emily-Spinelli.pdf
    • http://loaminoo.linkpc.net/1093099091099090/The-Spanish-Labyrinth-An-Account-of-the-Social-and-Political-Background-of-the-Spanish-Civil-War-by-Gerald-Brenan.pdf
    • http://loaminoo.linkpc.net/2098095094096099/The-Secret-Life-of-the-Love-Song-and-The-Flesh-Made-Word-Two-Lectures-by-Nick-Cave-by-Nick-Cave.pdf
    • http://loaminoo.linkpc.net/2094091092096/Spanish-Fever-Stories-by-the-New-Spanish-Cartoonists-by-Santiago-Garc-a.pdf
    • http://loaminoo.linkpc.net/9097099098091090/Household-Tales-and-Childrens-Legends-Household-Tales-and-Childrens-Legends-German-Learning-Edition-by-Jacob-Grimm.pdf
    • http://loaminoo.linkpc.net/1090095094096099097/Return-of-the-Spanish-Spanish-Bit-Saga-18-by-Don-Coldsmith.pdf
    • http://loaminoo.linkpc.net/4095092096091093/Trail-of-the-Spanish-Bit-Spanish-Bit-Saga-1-by-Don-Coldsmith.pdf
    • http://loaminoo.linkpc.net/1090094091092099094/Hohle-in-Amerika-Hohle-in-Nordamerika-Hohle-in-Sudamerika-Mammoth-Cave-Nationalpark-Penn-s-Cave-Muchimuk-Hohlensystem-Mine-Von-Naica-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/1090098093097099099/Accelerated-Spanish-Learn-fluent-Spanish-with-a-proven-accelerated-learning-system-by-Timothy-Moser.pdf
    • http://loaminoo.linkpc.net/9091091099097095/Danny-Duck-Tames-the-Lion-Danny-Pato-doma-al-Le-n---Bilingual-Book-in-English-and-Spanish-Study-Spanish-for-Kids-1-by-Colin-Hann.pdf
    • http://loaminoo.linkpc.net/6096092099092090/Practical-Dictionary-of-Latin-American-Proverbs-with-Spanish-French-Quebec-French-and-English-Parallels-600-proverbial-sayings-of-Spanish-speaking-America-by-Pierre-DesRuisseaux.pdf
    • http://loaminoo.linkpc.net/1090094095095090090/The-Original-1812-Grimm-Fairy-Tales-A-New-Translation-of-the-1812-First-Edition-Kinder-und-Hausm-rchen-Childrens-and-Household-Tales-1812-Childrens-and-Household-Tales-Kinder-und-Hausm-rchen-by-Oliver-Loo.pdf
    • http://loaminoo.linkpc.net/1096096095097098/1000-Spanish-Verbs-in-Context-A-Self-Study-Guide-for-Spanish-Language-Learners-Extra-FREE-Bonus-Material-Included-1000-Verb-Lists-in-Context-by-Alex-Forero.pdf