Malicious PDF — malware analysis report

Static analysis result for SHA-256 612da453753b8f46…

MALICIOUS

PDF

16.7 KB Created: 2019-04-30 05:32:18 +01:00 Authoring application: mPDF 5.7
MD5: 6ac7b28eb863efe77721ae01917c039a SHA-1: 5c516425b9887d89094d2efdd682eb095d92894e SHA-256: 612da453753b8f460bb0fbcc0c752f5bbc159ff8cfee51e99f7f86f8663d0e0d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, which is a common tactic for SEO manipulation or distributing malicious content. While no scripts were explicitly extracted, the heuristic 'PDF_SEO_LINK_FARM' and the presence of numerous external links suggest an attempt to redirect users to potentially harmful sites. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6096099092099/The-Force-Unleashed-Star-Wars-The-Force-Unleashed-1-by-Sean-Williams.pdf
    • http://loaminoo.linkpc.net/5098098094097091/Star-Wars-The-Force-Unleashed-II-The-Force-Unleashed-2-by-W-Haden-Blackman.pdf
    • http://loaminoo.linkpc.net/1099099096093098/Refugee-Force-Heretic-2-Star-Wars-The-New-Jedi-Order-16-by-Sean-Williams.pdf
    • http://loaminoo.linkpc.net/1096093099093090/Betrayal-Star-Wars-Legacy-of-the-Force-1-by-Aaron-Allston.pdf
    • http://loaminoo.linkpc.net/4090097090093094/Star-Wars-The-Force-Awakens-by-Alan-Dean-Foster.pdf
    • http://loaminoo.linkpc.net/3093099091092098/Sacrifice-Star-Wars-Legacy-of-the-Force-5-by-Karen-Traviss.pdf
    • http://loaminoo.linkpc.net/3093099091090093/Patterns-of-Force-Star-Wars-Coruscant-Nights-3-by-Michael-Reaves.pdf
    • http://loaminoo.linkpc.net/3093099093093093/The-Unifying-Force-Star-Wars-The-New-Jedi-Order-19-by-James-Luceno.pdf
    • http://loaminoo.linkpc.net/2094091097099092/Star-Wars-Dawn-of-the-Jedi-Volume-1-Force-Storm-by-John-Ostrander.pdf
    • http://loaminoo.linkpc.net/5095094090090095/1-Voyage-vers-Star-Wars-Le-r-veil-de-la-force---La-cavale-du-contrebandier-by-Greg-Rucka.pdf
    • http://loaminoo.linkpc.net/6097097098092094/3-Voyage-vers-Star-Wars-Le-r-veil-de-la-force---L-Arme-du-Jedi-by-Cecil-Castellucci.pdf
    • http://loaminoo.linkpc.net/3090093094095092/Fatal-Alliance-Star-Wars-The-Old-Republic-3-by-Sean-Williams.pdf
    • http://loaminoo.linkpc.net/1096092095097091/Star-Force-Nemesis-Star-Force-3-by-Aer-ki-Jyr.pdf
    • http://loaminoo.linkpc.net/1096093092098090/Star-Force-Fabrication-Star-Force-7-by-Aer-ki-Jyr.pdf
    • http://loaminoo.linkpc.net/3096094094092096/Star-Force-Deception-Star-Force-11-by-Aer-ki-Jyr.pdf
    • http://loaminoo.linkpc.net/3093094093094097/Star-Force-Inception-Star-Force-1-by-Aer-ki-Jyr.pdf
    • http://loaminoo.linkpc.net/1096092092092093/Star-Force-Integration-Star-Force-2-by-Aer-ki-Jyr.pdf
    • http://loaminoo.linkpc.net/3096094094092090/Star-Force-Flashpoint-Star-Force-8-by-Aer-ki-Jyr.pdf
    • http://loaminoo.linkpc.net/9095093098091097/Star-Wars-The-Old-Republic-Sammelband-Bd-1-Eine-unheilvolle-Allianz-Betrogen-by-Sean-Williams.pdf
    • http://loaminoo.linkpc.net/3090094092093096/William-Shakespeare-s-The-Force-Doth-Awaken-William-Shakespeare-s-Star-Wars-7-by-Ian-Doescher.pdf