Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c148d78f1c5e6a8…

MALICIOUS

PDF

20.8 KB Created: 2019-04-30 02:02:42 +01:00 Authoring application: mPDF 5.7
MD5: bb6d4533f7ab1c4720050a2851dd3998 SHA-1: 3ac61f9a1dc20594c097bd0452c5e1505ebbe0fe SHA-256: 5c148d78f1c5e6a87affed4ac6cfa189c914ebd210a7f12a0e49a149d694ed27
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, each pointing to a different PDF file. This pattern is indicative of SEO spam or a technique to host malicious content across many domains. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3092094092094099/It-s-Hell-To-Choose-The-Kurtherian-Gambit-9-by-Michael-Anderle.pdf
    • http://loaminoo.linkpc.net/3092094092094090/Never-Surrender-The-Kurtherian-Gambit-16-by-Michael-Anderle.pdf
    • http://loaminoo.linkpc.net/3094099090090091/Death-Becomes-Her-The-Kurtherian-Gambit-1-by-Michael-Anderle.pdf
    • http://loaminoo.linkpc.net/3092093099099098/Never-Forsaken-The-Kurtherian-Gambit-5-by-Michael-Anderle.pdf
    • http://loaminoo.linkpc.net/3092093099099097/My-Ride-is-a-Bitch-The-Kurtherian-Gambit-13-by-Michael-Anderle.pdf
    • http://loaminoo.linkpc.net/3092094094098096/Sued-For-Peace-The-Kurtherian-Gambit-11-by-Michael-Anderle.pdf
    • http://loaminoo.linkpc.net/3092093099099090/Queen-Bitch-The-Kurtherian-Gambit-2-by-Michael-Anderle.pdf
    • http://loaminoo.linkpc.net/3092093099099096/Love-Lost-The-Kurtherian-Gambit-3-by-Michael-Anderle.pdf
    • http://loaminoo.linkpc.net/4093093096093099/Damned-To-Hell-A-Kurtherian-Gambit-Series-Trials-And-Tribulations-2-by-Natalie-Grey.pdf
    • http://loaminoo.linkpc.net/3092094092093098/Called-Age-Of-Expansion---A-Kurtherian-Gambit-Series-The-Ascension-Myth-3-by-Ell-Leigh-Clarke.pdf
    • http://loaminoo.linkpc.net/3092094094097093/Judgment-Has-Fallen-A-Kurtherian-Gambit-Series-Reclaiming-Honor-3-by-Justin-Sloan.pdf
    • http://loaminoo.linkpc.net/3092094092094093/Justice-Is-Calling-A-Kurtherian-Gambit-Series-Reclaiming-Honor-1-by-Justin-Sloan.pdf
    • http://loaminoo.linkpc.net/1091094097090099091/Preservation-Age-of-Expansion---A-Kurtherian-Gambit-Series-The-Ghost-Squadron-7-by-Sarah-Noffke.pdf
    • http://loaminoo.linkpc.net/3092094092093093/Sanctioned-Age-Of-Expansion---A-Kurtherian-Gambit-Series-The-Ascension-Myth-4-by-Ell-Leigh-Clarke.pdf
    • http://loaminoo.linkpc.net/1091094097090093099/Obliteration-Age-Of-Expansion-A-Kurtherian-Gambit-Series-Precious-Galaxy-4-by-Sarah-Noffke.pdf
    • http://loaminoo.linkpc.net/1091094096099096091/Prime-Enforcer-Age-of-Expansion---A-Kurtherian-Gambit-Series-Valerie-s-Elites-3-by-Justin-Sloan.pdf
    • http://loaminoo.linkpc.net/3092095093090099/Darkness-Rises-Age-Of-Magic---A-Kurtherian-Gambit-Series-The-Rise-of-Magic-6-by-C-M-Raymond.pdf
    • http://loaminoo.linkpc.net/3092095092098095/The-Arcadian-Druid-Age-Of-Magic---A-Kurtherian-Gambit-Series-Tales-of-the-Feisty-Druid-1-by-Candy-Crum.pdf
    • http://loaminoo.linkpc.net/7090097091091091/Falling-in-Love-Why-We-Choose-the-Lovers-We-Choose-by-Ayala-Malach-Pines.pdf
    • http://loaminoo.linkpc.net/2090096099092091/The-Necromancer-s-Gambit-The-Gambit-1-by-Nicolas-Wilson.pdf