Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f0e441d76aa46b9…

MALICIOUS

PDF

21.7 KB Created: 2019-05-03 09:12:23 +01:00 Authoring application: mPDF 5.7
MD5: 9742da308722c39a0d32a0f1a5a5be23 SHA-1: f29a6a7c947aaa593b23027dece78e994dc6bc1d SHA-256: 5f0e441d76aa46b916f6296e4f5bb6eb82480d0624d748bdcb3c925a4f4ec15b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which point to external PDF files. These links are presented in a way that suggests they are book downloads, likely to trick users into clicking them. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of this document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9099098092098/Assassin-s-Creed-Black-Flag-Assassin-s-Creed-6-by-Oliver-Bowden.pdf
    • http://loaminoo.linkpc.net/6091091093095093/Assassin-s-Creed-Underworld-Assassin-s-Creed-8-by-Oliver-Bowden.pdf
    • http://loaminoo.linkpc.net/1090091092095096/Assassin-s-Creed-Brotherhood-Assassin-s-Creed-2-by-Oliver-Bowden.pdf
    • http://loaminoo.linkpc.net/4094095096097095/Assassin-s-Creed-Renaissance-by-Oliver-Bowden.pdf
    • http://loaminoo.linkpc.net/6091091099096094/Assassin-s-Creed---Assassin-s-Creed-Brotherhood-Characters-Agostino-Chigi-Aldo-Angelina-Ceresa-Auguste-Oberlin-Bartolomeo-D-Alviano-Battista-Borgia-Bayezid-II-Belardino-Da-Verona-Caterina-Sforza-Cesare-Borgia-Claudia-Auditore-Da-Firenze-Claud-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/3093096091095092/The-Invisible-Imam-Assassin-s-Creed-1-by-Steven-Barnes.pdf
    • http://loaminoo.linkpc.net/4097094099096091/Assassin-s-Creed-Assassins-Vol-1-Trial-by-Fire-by-Anthony-Del-Col.pdf
    • http://loaminoo.linkpc.net/1090096092097090098/Assassin-s-Creed-Free-Comic-Book-Day-2016-by-Anthony-Del-Col.pdf
    • http://loaminoo.linkpc.net/4090095090091098/Silent-Creed-Ryder-Creed-2-by-Alex-Kava.pdf
    • http://loaminoo.linkpc.net/2096098093099090/Breaking-Creed-Ryder-Creed-1-by-Alex-Kava.pdf
    • http://loaminoo.linkpc.net/1095093/Breaking-Creed-Ryder-Creed-1-by-Alex-Kava.pdf
    • http://loaminoo.linkpc.net/8092096092090091/Reckless-Creed-Ryder-Creed-3-by-Alex-Kava.pdf
    • http://loaminoo.linkpc.net/4095096097091092/Crossover-Devil-s-Due-MC-and-Vipers-Creed-MC-Prequel-Devil-s-Due-MC-0-5-Viper-s-Creed-MC-0-5-by-Chelsea-Camaron.pdf
    • http://loaminoo.linkpc.net/1091093097097097/Diver-Creed-Station-by-Oliver-Phipps.pdf
    • http://loaminoo.linkpc.net/3099095091096/Assassin-s-Apprentice-Royal-Assassin-Farseer-Trilogy-1-2-by-Robin-Hobb.pdf
    • http://loaminoo.linkpc.net/1091098096093099/Prayers-for-the-Assassin-Assassin-Trilogy-1-by-Robert-Ferrigno.pdf
    • http://loaminoo.linkpc.net/1091095097092096/The-Heart-of-an-Assassin-Assassin-Trilogy-2-by-Tony-Bertot.pdf
    • http://loaminoo.linkpc.net/5094090090096/Novels-By-Robin-Hobb-including-Assassin-s-Apprentice-Royal-Assassin-Assassin-s-Quest-Fool-s-Errand-novel-The-Golden-Fool-Shaman-s-Crossing-Fool-s-Fate-Ship-Of-Magic-Forest-Mage-Renegade-s-Magic-Dragon-Keeper-hobb-Novel-Ship-Of-Destiny-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/6091091093093091/Night-of-the-Assassin-Assassin-0-5-by-Russell-Blake.pdf
    • http://loaminoo.linkpc.net/3095098093091092/Sinner-s-Creed-Sinner-s-Creed-MC-1-by-Kim-Jones.pdf