Malicious PDF — malware analysis report

Static analysis result for SHA-256 62669e3e2b8fbdb1…

MALICIOUS

PDF

18.1 KB Created: 2019-05-05 16:08:58 +01:00 Authoring application: mPDF 5.7
MD5: edfde2adb71d076dcd115f723534c428 SHA-1: c2f25f65809a2bd8a82d79c87169d767e8728c07 SHA-256: 62669e3e2b8fbdb121c5188e27428a1f4b4229b217c7b3228906981863c23916
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, which is a common tactic for SEO manipulation or distributing malicious payloads. While the document body is corrupted, the heuristic firings and the presence of numerous external URLs strongly suggest a malicious intent to redirect users. No scripts were extracted, but the embedded links are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1094091099099/Beauty-A-Retelling-of-the-Story-of-Beauty-and-the-Beast-by-Robin-McKinley.pdf
    • http://loaminoo.linkpc.net/8097097091090/Beauty-A-Retelling-of-the-Story-of-Beauty-and-the-Beast-by-Robin-McKinley.pdf
    • http://loaminoo.linkpc.net/2090094091092098/Isabelle-and-the-Beast-A-Retelling-of-Beauty-and-the-Beast-by-Dee-J-Stone.pdf
    • http://loaminoo.linkpc.net/4093091094096094/Beauty-and-the-Beast-A-Modern-Retelling-by-Nicolette-Gianni.pdf
    • http://loaminoo.linkpc.net/6098092099092/Beauty-by-Robin-McKinley.pdf
    • http://loaminoo.linkpc.net/2095099093094093/Beauty-by-Robin-McKinley.pdf
    • http://loaminoo.linkpc.net/4093091094095096/Rose-and-the-Monster-A-Modern-Retelling-of-Beauty-and-the-Beast-by-M-Lowry.pdf
    • http://loaminoo.linkpc.net/1095095097097091/Beauty-Sleep-A-Retelling-of-Sleeping-Beauty-by-Cameron-Dokey.pdf
    • http://loaminoo.linkpc.net/3097090097099094/Hunted-An-Erotic-Retelling-of-Beauty-and-the-Beast-Hunted-by-the-Beast-1-5-by-Cerys-du-Lys.pdf
    • http://loaminoo.linkpc.net/4094090094096092/Beauty-and-Beastly-Steampunk-Fairy-Tales-Beauty-and-the-Beast-1-by-Melanie-Karsak.pdf
    • http://loaminoo.linkpc.net/2090090095094095/Beauty-Touched-the-Beast-Beauty-1-by-Skye-Warren.pdf
    • http://loaminoo.linkpc.net/2097096091096099/Roses-in-Amber-A-Beauty-and-the-Beast-story-by-C-E-Murphy.pdf
    • http://loaminoo.linkpc.net/1091091094090098094/Beauty-and-the-Beast-The-Story-of-Nastassja-and-Klaus-Kinski-by-W-A-Harbinson.pdf
    • http://loaminoo.linkpc.net/1090090093093094093/The-Works-of-Dinah-Maria-Mulock-Craik-The-Sleeping-Beauty-In-The-Wood-Cinderella-Beauty-And-The-Beast-Rumpelstilzchen-Little-Red-Riding-Hood-Puss-Prince-and-More-50-Books-and-Stories-by-Dinah-Maria-Mulock-Craik.pdf
    • http://loaminoo.linkpc.net/4092091090095/Beauty-and-the-Beastly-Earl-A-Fairytale-Retelling-Book-2-by-Regina-James.pdf
    • http://loaminoo.linkpc.net/2098095095096095/The-Beauty-s-Beast-by-E-D-Walker.pdf
    • http://loaminoo.linkpc.net/2097096093092099/The-Beauty-of-a-Beast-by-starofjems.pdf
    • http://loaminoo.linkpc.net/4097090092092092/Disney-s-Beauty-and-the-Beast-by-A-L-Singer.pdf
    • http://loaminoo.linkpc.net/2094099092096093/Beauty-and-the-Beast-by-Deatri-King-Bey.pdf
    • http://loaminoo.linkpc.net/1097092092099090/Beauty-and-the-Beast-by-Ursula-Jones.pdf