Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e27b6b104d9852f…

MALICIOUS

PDF

18.3 KB Created: 2019-04-30 03:49:10 +01:00 Authoring application: mPDF 5.7
MD5: de3ee9c6d935f226979154a5d9a2e6cf SHA-1: 746ed428c48df931042dcfd46d0e3ede0c380054 SHA-256: 5e27b6b104d9852fc6138e51557517062a0d5707d3e052d37f50dc0498f01c01
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on a dynamic DNS domain. This behavior is indicative of a link farm or a content-luring scheme, potentially designed to distribute malicious content or drive traffic. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099093094096098/Mars-Evacuees-Mars-Evacuees-1-by-Sophia-McDougall.pdf
    • http://loaminoo.linkpc.net/5096093096091093/A-Princess-of-Mars-Gods-of-Mars-Warlord-of-Mars-Thuvia-Maid-of-Mars-Chessmen-of-Mars-Master-Mind-of-Mars-Fighting-Man-of-Mars-Barsoom-1-7-by-Edgar-Rice-Burroughs.pdf
    • http://loaminoo.linkpc.net/6097096098094094/Mars-Planet-Marsmeteorit-Mars-Trojaner-Darischer-Kalender-Mars-to-Stay-Marskolonisation-Bemannter-Marsflug-Mars-500-Phobos-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/1095099098093090/Red-Mars-Green-Mars-Mars-Trilogy-1-2-by-Kim-Stanley-Robinson.pdf
    • http://loaminoo.linkpc.net/3095092099098093/Blue-Mars-Mars-Trilogy-3-by-Kim-Stanley-Robinson.pdf
    • http://loaminoo.linkpc.net/5096093096091094/MARS-Horse-With-No-Name-Mars-16-by-Fuyumi-Soryo.pdf
    • http://loaminoo.linkpc.net/8099097096094098/Mars-One-The-Human-Factor-Inside-the-Selection-Adventure-and-Challenges-of-the-First-Human-Settlement-on-Mars-by-Norbert-Kraft.pdf
    • http://loaminoo.linkpc.net/1091098095097096090/Mars---der-W-stenplanet-In-der-Galaxis-Milchstrasse-war-der-Mars-als-der-W-stenplanet-bekannt-by-Walter-Guttropf.pdf
    • http://loaminoo.linkpc.net/4095090090091/Saving-Mars-Saving-Mars-1-by-Cidney-Swanson.pdf
    • http://loaminoo.linkpc.net/1097093090098097/Rome-Burning-Romanitas-2-by-Sophia-McDougall.pdf
    • http://loaminoo.linkpc.net/1098092092099091/Mars-by-Ben-Bova.pdf
    • http://loaminoo.linkpc.net/9092091094096097/Man-From-Mars-by-Stanis-aw-Lem.pdf
    • http://loaminoo.linkpc.net/9099097099095093/Invaders-From-Mars-by-Ray-Garton.pdf
    • http://loaminoo.linkpc.net/2091093098095090/Children-of-Mars-by-Paul-G-Day.pdf
    • http://loaminoo.linkpc.net/2094094094097/How-We-Went-to-Mars-by-Arthur-C-Clarke.pdf
    • http://loaminoo.linkpc.net/2093095099091093/Never-Been-to-Mars-by-Larry-Gent.pdf
    • http://loaminoo.linkpc.net/1090091097093096096/Champion-of-Mars-by-Guy-Haley.pdf
    • http://loaminoo.linkpc.net/6097096096097097/From-Phobos-to-Mars-by-K-Van-Kramer.pdf
    • http://loaminoo.linkpc.net/8090095093092097/There-s-Nothing-to-Do-on-Mars-by-Chris-Gall.pdf
    • http://loaminoo.linkpc.net/3099093096095095/The-Mars-Mystery-by-Graham-Hancock.pdf