Malicious PDF — malware analysis report

Static analysis result for SHA-256 63b339caf6dbff62…

MALICIOUS

PDF

16.5 KB Created: 2019-04-30 05:26:53 +01:00 Authoring application: mPDF 5.7
MD5: 24beac3164a3c1ee7b1e7cd90e9422c2 SHA-1: 23c0e35fad73c1ec9d5ab1ff3a22e4d28dbf9bbc SHA-256: 63b339caf6dbff62b056712b2a993d7bbb71fad8bd0a23e5e12e858c94e99113
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to external PDF files. This behavior is indicative of a link farm or a method to distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3099092096095096/Something-About-You-FBI-US-Attorney-1-by-Julie-James.pdf
    • http://loaminoo.linkpc.net/3090091098093092/Something-About-You-FBI-US-Attorney-1-by-Julie-James.pdf
    • http://loaminoo.linkpc.net/3090093092094/About-That-Night-by-Julie-James.pdf
    • http://loaminoo.linkpc.net/7098099096095097/James-Havard-by-Julie-Sasse.pdf
    • http://loaminoo.linkpc.net/3091092092093097/Finnigan-the-Dragon-by-Julie-Ann-James.pdf
    • http://loaminoo.linkpc.net/4095097092099096/Just-the-Sexiest-Man-Alive-by-Julie-James.pdf
    • http://loaminoo.linkpc.net/3099097099093091/Practice-Makes-Perfect-by-Julie-James.pdf
    • http://loaminoo.linkpc.net/2091091090098093/Across-the-James-Bay-Bridge-Our-Canadian-Girl-Emily-1-by-Julie-Lawson.pdf
    • http://loaminoo.linkpc.net/2091092094091/James-Tiptree-Jr-The-Double-Life-of-Alice-B-Sheldon-by-Julie-Phillips.pdf
    • http://loaminoo.linkpc.net/4090094094095092/Phoenix-Wright-Ace-Attorney-1-by-Kenji-Kuroda.pdf
    • http://loaminoo.linkpc.net/8096091098093/Power-of-Attorney-Lawyers-in-Love-5-by-N-M-Silber.pdf
    • http://loaminoo.linkpc.net/3099096099093094/Power-of-Attorney-Lawyers-in-Love-5-by-N-M-Silber.pdf
    • http://loaminoo.linkpc.net/5090093095092092/Attorney-at-Large-Thaddeus-Murfee-Legal-Thriller-3-by-John-Ellsworth.pdf
    • http://loaminoo.linkpc.net/3098096091099/Julie-and-Julia-365-Days-524-Recipes-1-Tiny-Apartment-Kitchen-by-Julie-Powell.pdf
    • http://loaminoo.linkpc.net/2099093094094099/Julie-amp-Julia-365-days-524-recipes-1-tiny-apartment-kitchen-by-Julie-Powell.pdf
    • http://loaminoo.linkpc.net/1094092095090091/Julie-s-Journey-American-Girls-Julie-5-by-Megan-McDonald.pdf
    • http://loaminoo.linkpc.net/1094092095097090/Julie-and-the-Eagles-American-Girls-Julie-4-by-Megan-McDonald.pdf
    • http://loaminoo.linkpc.net/1094092094091097/Changes-for-Julie-American-Girls-Julie-6-by-Megan-McDonald.pdf
    • http://loaminoo.linkpc.net/1092095097099095/Notes-from-an-American-Jail-One-attorney-s-60-days-in-the-New-Haven-County-Jail-by-Jean-Claude-Dehmel-II.pdf
    • http://loaminoo.linkpc.net/2092094097097090/Father-Son-and-Constitution-How-Justice-Tom-Clark-and-Attorney-General-Ramsey-Clark-Shaped-American-Democracy-by-Alexander-Wohl.pdf