Malicious PDF — malware analysis report

Static analysis result for SHA-256 6325e5a081e791cb…

MALICIOUS

PDF

15.7 KB Created: 2019-05-02 01:40:29 +01:00 Authoring application: mPDF 5.7
MD5: 78d68f96979780b6f7761335fabd7a49 SHA-1: e088a2a57eecf5ec0d87381c37bbedbfbefca6d0 SHA-256: 6325e5a081e791cb5d87d5c9c7f4a17c4d928f1aae34b5e78beb25a147762b80
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2094098099097/Darwin-s-Radio-Darwin-s-Radio-1-by-Greg-Bear.pdf
    • http://loaminoo.linkpc.net/7099097095096/Darwin-s-Children-Darwin-s-Radio-2-by-Greg-Bear.pdf
    • http://loaminoo.linkpc.net/6099097095096/Kill-the-Radio---Sebuah-Radio-Kumatikan-by-Dorothea-Rosa-Herliany.pdf
    • http://loaminoo.linkpc.net/1090096094090095096/Sound-Reporting-The-National-Public-Radio-Guide-to-Radio-Journalism-and-Production-by-John-Dinges.pdf
    • http://loaminoo.linkpc.net/8094090098097096/Hey-Darwin-at-the-Zu-Daily-Strips-Volume-1-Darwin-amp-Co-and-Stoopid-Zu-Cartoons-by-Ron-Ruelle.pdf
    • http://loaminoo.linkpc.net/6095093094097093/The-Darwin-Awards-II-Unnatural-Selection-Darwin-Awards-2-by-Wendy-Northcutt.pdf
    • http://loaminoo.linkpc.net/4098099094092/The-Darwin-Awards-Evolution-in-Action-Darwin-Awards-1-by-Wendy-Northcutt.pdf
    • http://loaminoo.linkpc.net/5098098092090096/On-The-Origin-Of-Species-By-Charles-Darwin---Illustrated-by-Charles-Darwin.pdf
    • http://loaminoo.linkpc.net/1091099090093092091/The-Autobiography-of-Charles-Darwin-1809-82-by-Charles-Darwin.pdf
    • http://loaminoo.linkpc.net/7092098095097/The-Autobiography-of-Charles-Darwin-by-Charles-Darwin.pdf
    • http://loaminoo.linkpc.net/1090097095092096090/Angel-Radio-by-A-M-Blaushild.pdf
    • http://loaminoo.linkpc.net/7099093098090098/Radio-Golf-by-August-Wilson.pdf
    • http://loaminoo.linkpc.net/3090095098098099/Fridays-with-Red-A-Radio-Friendship-by-Bob-Edwards.pdf
    • http://loaminoo.linkpc.net/3095092099099096/Radio-Freefall-by-Matthew-Jarpe.pdf
    • http://loaminoo.linkpc.net/4091092096099099/First-Ladies-by-National-Public-Radio.pdf
    • http://loaminoo.linkpc.net/2092097094093094/Radio-Hope-by-Sean-McLachlan.pdf
    • http://loaminoo.linkpc.net/3090090090091095/WLT-A-Radio-Romance-by-Garrison-Keillor.pdf
    • http://loaminoo.linkpc.net/1090097095093098097/Radio-Activity-by-Bill-Fitzhugh.pdf
    • http://loaminoo.linkpc.net/3095099094097096/Zombie-Radio-by-Jack-Wallen.pdf
    • http://loaminoo.linkpc.net/7096092091097090/Darwin-s-Blade-by-Dan-Simmons.pdf