Malicious PDF — malware analysis report

Static analysis result for SHA-256 61c5c7434c3807f6…

MALICIOUS

PDF

21.8 KB Created: 2019-05-02 08:22:14 +01:00 Authoring application: mPDF 5.7
MD5: 603ba269e7f232c1f54bc2b9dc42ffed SHA-1: 6ff9e3cd711625fd8b80c39ca60c25eb960ead13 SHA-256: 61c5c7434c3807f6a7e839ed82fc94855029050256ff00998d952430cfa20bd3
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to what appear to be benign book titles, the sheer volume and the use of a dynamic DNS hostname suggest a potential attempt at SEO manipulation or a distribution point for malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092092092091098/Tellus-Tales-Volume-1-The-Wildlands-Tellus-Tales-1-by-Brian-Berg.pdf
    • http://loaminoo.linkpc.net/3094090090095093/Star-Wars-Tales-Omnibus-Tales-from-the-Mos-Eisley-Cantina-Tales-of-the-Bounty-Hunters-and-Tales-from-Jabba-s-Palace-by-Kevin-J-Anderson.pdf
    • http://loaminoo.linkpc.net/4097096094092098/Grimms-Fairy-Tales-Volume-2-Sleeping-Beauty-and-Other-Tales-by-Jacob-Grimm.pdf
    • http://loaminoo.linkpc.net/4097095090097093/Pet-Tales-Tabby-Cat-Tales-and-Guinea-Pig-Tales-by-Becky-Corwin-Adams.pdf
    • http://loaminoo.linkpc.net/1095098091094090/Drenai-Tales-Volume-Three-Drenai-Tales-7-9-by-David-Gemmell.pdf
    • http://loaminoo.linkpc.net/1095098091095090/Drenai-Tales-Volume-One-Drenai-Tales-1-3-by-David-Gemmell.pdf
    • http://loaminoo.linkpc.net/6095098095097091/Greatest-Russian-Fairytales-amp-Fables-Illustrated-Over-125-Stories-Including-Picture-Tales-for-Children-Old-Peter-s-Russian-Tales-Muscovite-Folk-Tales-for-Adults-and-Others-Annotated-Edition-by-Valery-Carrick.pdf
    • http://loaminoo.linkpc.net/1098094093098098/Seven-Strange-and-Ghostly-Tales-by-Brian-Jacques.pdf
    • http://loaminoo.linkpc.net/7095091092094093/Not-A-Match-My-True-Tales-of-Online-Dating-Disasters-by-Brian-Donovan.pdf
    • http://loaminoo.linkpc.net/4094094098094094/Twisted-Tales-Six-Fairy-Tales-Turned-Inside-Out-by-Richard-Tulloch.pdf
    • http://loaminoo.linkpc.net/3098098095093096/Tales-of-Moonlight-and-Rain-Japanese-Gothic-Tales-by-Ueda-Akinari.pdf
    • http://loaminoo.linkpc.net/9091095099098/Her-Stories-African-American-Folktales-Fairy-Tales-and-True-Tales-by-Virginia-Hamilton.pdf
    • http://loaminoo.linkpc.net/2091095093099099/A-Sea-of-Words-A-Lexicon-and-Companion-to-the-Complete-Seafaring-Tales-of-Patrick-O-Brian-by-Dean-King.pdf
    • http://loaminoo.linkpc.net/4099094096095096/Tales-of-Passion-Tales-of-Woe-Josephine-Bonaparte-2-by-Sandra-Gulland.pdf
    • http://loaminoo.linkpc.net/1091095093092098097/Epic-Tales-Norse-Myths-amp-Tales-by-Brittany-Schorn.pdf
    • http://loaminoo.linkpc.net/1099090099095098/The-Canterbury-Tales-Nine-Tales-and-the-General-Prologue-Authoritative-Text-Sources-and-Backgrounds-Criticism-by-Geoffrey-Chaucer.pdf
    • http://loaminoo.linkpc.net/2098097091093093/They-Call-Me-Killer-Tales-from-Junior-Hockey-s-Legendary-Hall-Of-Fame-Coach-by-Brian-Kilrea.pdf
    • http://loaminoo.linkpc.net/2093092090097090/Tales-of-the-Grotesque-A-Collection-of-Uneasy-Tales-by-L-A-Lewis.pdf
    • http://loaminoo.linkpc.net/4095099095091097/Kinky-Tales-Volume-1-by-T-L-Hayes.pdf
    • http://loaminoo.linkpc.net/1095098094092098/Tales-of-Erana-Volume-I-by-A-L-Butcher.pdf