Malicious PDF — malware analysis report

Static analysis result for SHA-256 62af4b0fc8543f5f…

MALICIOUS

PDF

22.0 KB Created: 2019-04-30 02:50:20 +01:00 Authoring application: mPDF 5.7
MD5: 69c94deab47e9f20c21008eb237ff56f SHA-1: cc5d6c711ca3b8361f8b6d177de40c3c1d799dd1 SHA-256: 62af4b0fc8543f5fb7889c77d1fb61413314833ffad6e84b35d5fc46004fcdac
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection tactic. While the document body is unreadable, the presence of numerous external links points towards an attempt to drive traffic or potentially distribute further malicious content. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicates malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097090096099093/Le-Bateau-Ivre-in-French-and-Japanese-Rimbeau-Malarme-Bertrand-Ueda-Bin-Translations-and-Original-Texts-by-Ueda-Bin.pdf
    • http://loaminoo.linkpc.net/3098098095093096/Tales-of-Moonlight-and-Rain-Japanese-Gothic-Tales-by-Ueda-Akinari.pdf
    • http://loaminoo.linkpc.net/2099092097094094/Lettres-d-une-Peruvienne-Texts-and-Translations-Texts-No-2-by-Fran-oise-de-Graffigny.pdf
    • http://loaminoo.linkpc.net/6091090093092098/Une-saison-en-enfer-amp-Le-bateau-ivre-A-season-in-hell-amp-The-drunken-boat-A-New-Directions-paperbook-by-Arthur-Rimbaud.pdf
    • http://loaminoo.linkpc.net/8094098094097093/The-Cage-of-Zeus-by-Sayuri-Ueda.pdf
    • http://loaminoo.linkpc.net/7097090098092093/Matsuo-Bash-by-Makoto-Ueda.pdf
    • http://loaminoo.linkpc.net/1096098099092091/Tail-of-the-Moon-Volume-3-by-Rinko-Ueda.pdf
    • http://loaminoo.linkpc.net/1096098090096096/Tail-of-the-Moon-Volume-15-by-Rinko-Ueda.pdf
    • http://loaminoo.linkpc.net/1093099091093090/Tales-of-Moonlight-and-Rain-by-Ueda-Akinari.pdf
    • http://loaminoo.linkpc.net/1096098096093090/Tail-of-the-Moon-Volume-9-by-Rinko-Ueda.pdf
    • http://loaminoo.linkpc.net/1096098093090097/Tail-of-the-Moon-Volume-12-by-Rinko-Ueda.pdf
    • http://loaminoo.linkpc.net/2093097091097091/Tail-of-the-Moon-Prequel-The-Other-Hanzo-u-by-Rinko-Ueda.pdf
    • http://loaminoo.linkpc.net/5095092091094097/Familypedia---French-Language-Articles-in-French-French-Speaking-Countries-La-Francophonie-Pages-in-French-Translations-Needed-Fr-User-Fr-Abraham-Coste-Baronnet-Beaudet-Brice-Baronnet-Charles-Borromee-Beaudet-Charles-Baronnet-by-Source-Wikia.pdf
    • http://loaminoo.linkpc.net/2092097098099091/Peach-Girl-Change-of-Heart-Vol-6-Peach-Girl-14-by-Miwa-Ueda.pdf
    • http://loaminoo.linkpc.net/2092098097099090/Peach-Girl-Change-of-Heart-Vol-2-Peach-Girl-10-by-Miwa-Ueda.pdf
    • http://loaminoo.linkpc.net/5093092093090095/Troubled-Souls-From-Japanese-Noh-Plays-of-the-Fourth-Group-Parallel-Translations-with-Running-Commentary-by-Chifumi-Shimazaki.pdf
    • http://loaminoo.linkpc.net/5096099098093093/Beth-the-Baby-Boat-and-an-Unexpected-Friend-A-Children-s-Picture-Book---Cl-o-le-petit-bateau-et-une-amie-inattendue-Album-illustr---Bilingual-Edition-English-French-by-Silvano-Martina.pdf
    • http://loaminoo.linkpc.net/2092098098091093/Peach-Girl-Vol-4-Peach-Girl-4-by-Miwa-Ueda.pdf
    • http://loaminoo.linkpc.net/2092098098095090/Peach-Girl-Vol-5-Peach-Girl-5-by-Miwa-Ueda.pdf
    • http://loaminoo.linkpc.net/2092098096094098/Stepping-on-Roses-Vol-4-Stepping-on-Roses-4-by-Rinko-Ueda.pdf