Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e0d8dc2d37e3d3f…

MALICIOUS

PDF

17.6 KB Created: 2019-04-30 03:05:15 +01:00 Authoring application: mPDF 5.7
MD5: ae141ba502f5c468cecb1289399bbb78 SHA-1: 9c9c0fea270127e0cecec87c9ec786ab4c65d121 SHA-256: 5e0d8dc2d37e3d3f7adca46d38056a7759109aa5a8bc4b76054693a7d3529b2f
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. These links point to various URLs hosted on 'linkpc.net', suggesting a link farm or redirection scheme. The ML classifier and ClamAV detection further support the malicious nature of this file, classifying it as a dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-9065515-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9065515-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091094090094093095/The-Call-of-the-Cthulhu-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/8092094092092097/Littlest-Lovecraft-The-Call-of-Cthulhu-by-Tro-Rex.pdf
    • http://loaminoo.linkpc.net/6091094096091092/The-Call-of-Cthulhu---Illustrated-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/4091096091099090/The-Call-of-Cthulhu-and-Other-Weird-Stories-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/5096096097092093/Call-of-Cthulhu-Fantasy-Roleplaying-in-the-Worlds-of-H-P-Lovecraft-by-Sandy-Petersen.pdf
    • http://loaminoo.linkpc.net/9099090092095092/The-Art-of-H-P-Lovecraft-s-the-Cthulhu-Mythos-by-Pat-Harrigan.pdf
    • http://loaminoo.linkpc.net/3090097097098097/The-Children-of-Cthulhu-Chilling-New-Tales-Inspired-by-H-P-Lovecraft-by-John-Pelan.pdf
    • http://loaminoo.linkpc.net/1099093098098093/Call-of-Cthulhu-D20-Roleplaying-Game-by-Monte-Cook.pdf
    • http://loaminoo.linkpc.net/1093099096090094/Call-of-Cthulhu-Horror-Roleplaying-by-Sandy-Petersen.pdf
    • http://loaminoo.linkpc.net/1099093097098091/Reign-of-Terror-Epic-Call-of-Cthulhu-Adventures-in-Revolutionary-France-by-Mark-Morrison.pdf
    • http://loaminoo.linkpc.net/9099090093092091/Dissecting-Cthulhu-Essays-on-the-Cthulhu-Mythos-by-S-T-Joshi.pdf
    • http://loaminoo.linkpc.net/3095094098099095/In-the-Belly-of-the-Beast-and-Other-Tales-of-Cthulhu-Wars-A-Cthulhu-Wars-Novel-by-Ben-Monroe.pdf
    • http://loaminoo.linkpc.net/1095095094094098/The-Complete-Works-of-H-P-Lovecraft-Volume-1-70-Horror-Short-Stories-Novels-and-Juvenilia-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/7094097098093/The-Dream-Cycle-of-H-P-Lovecraft-Dreams-of-Terror-and-Death-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/1095095093092096/The-Complete-Works-of-H-P-Lovecraft-102-Horror-Short-Stories-Novels-Juvenelia-Collaborations-and-Ghost-Writings-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/1099095097095094/O-Fortunate-Floridian-H-P-Lovecraft-s-Letters-to-R-H-Barlow-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/3098097090099093/The-Lovecraft-Library-Volume-1-Horror-Out-of-Arkham-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/6090093095097096/The-Complete-Fiction-of-H-P-Lovecraft-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/6090093095098091/The-Essential-H-P-Lovecraft-Collection-by-H-P-Lovecraft.pdf
    • http://loaminoo.linkpc.net/6090093095096096/The-Definitive-H-P-Lovecraft-by-H-P-Lovecraft.pdf