Malicious PDF — malware analysis report

Static analysis result for SHA-256 63ba66cdd9096f73…

MALICIOUS

PDF

21.9 KB Created: 2019-04-30 08:59:49 +01:00 Authoring application: mPDF 5.7
MD5: fbae1fdbc3d8d17d54d76927c06698b6 SHA-1: d1e4f058f2682903aa64f5cc5a03a0ce389b4380 SHA-256: 63ba66cdd9096f731b2588c75db18143b3a6820e47fb8ebac12853ca780e3388
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, suggesting a link farm or a method to distribute further malicious content. The ML classifier strongly flagged this PDF as malicious, and the heuristic indicates a mass external PDF link farm. The URLs themselves appear to be benign, but their sheer volume and the context of the heuristic suggest a malicious intent to direct users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090093096090096090/25-Best-Most-Versatile-Flies-Their-Histories-Stories-amp-Step-by-Step-Tying-Photos-by-Al-Ritt.pdf
    • http://loaminoo.linkpc.net/2097095095093093/Plot-Whisperer-Workbook-Step-by-Step-Exercises-to-Help-You-Create-Compelling-Stories-by-Martha-Alderson.pdf
    • http://loaminoo.linkpc.net/4097091093094095/Creature-Cookies-Step-by-Step-Instructions-and-80-Decorating-Ideas-You-Can-Do-by-Autumn-Carpenter.pdf
    • http://loaminoo.linkpc.net/5092097098090095/The-Colored-Pencil-Manual-Step-by-Step-Instructions-and-Techniques-by-Veronica-Winters.pdf
    • http://loaminoo.linkpc.net/8099096097099090/First-Time-Stranded-Knitting-Step-by-step-Basics-Plus-2-Projects-by-Lori-Ihnen.pdf
    • http://loaminoo.linkpc.net/9095090099091096/Weber-s-Way-to-Grill-The-Step-by-Step-Guide-to-Expert-Grilling-by-Jamie-Purviance.pdf
    • http://loaminoo.linkpc.net/1091094090094099098/The-True-Story-of-Pocahontas-Step-Into-Reading-Step-3-by-Lucille-Recht-Penner.pdf
    • http://loaminoo.linkpc.net/2092093095092/Weight-Training-Without-Injury-Over-350-Step-By-Step-Pictures-Including-What-Not-to-Do-by-Fred-Stellabotte.pdf
    • http://loaminoo.linkpc.net/8098095099098094/First-Time-Knitting-Step-by-Step-Basics-and-Easy-Projects-by-Carri-Hammett.pdf
    • http://loaminoo.linkpc.net/6094099094090098/Python-Programming-Step-by-Step-Guide-from-Beginners-to-Expert-by-ADRIEN-AIDA.pdf
    • http://loaminoo.linkpc.net/1090091096097094097/Sink-into-Sleep-A-Step-by-Step-Workbook-for-Reversing-Insomnia-by-Judith-R-Davidson.pdf
    • http://loaminoo.linkpc.net/8093099098097094/How-To-Hack-Like-a-Pornstar-A-Step-By-Step-Process-For-Breaking-Into-A-Bank-by-Sparc-Flow.pdf
    • http://loaminoo.linkpc.net/7092095097093097/How-You-Can-Start-and-Manage-Your-Own-Business-Complete-Step-By-Step-Guide-by-N-O-O-Ejiga.pdf
    • http://loaminoo.linkpc.net/3093095098098092/Baseball-Ballerina-Strikes-Out-Step-Into-Reading-Step-3-by-Kathryn-Cristaldi.pdf
    • http://loaminoo.linkpc.net/9092092091091092/Your-First-1000-Copies-The-Step-by-Step-Guide-to-Marketing-Your-Book-by-Tim-Grahl.pdf
    • http://loaminoo.linkpc.net/9098097092090098/Research-Methodology-A-Step-By-Step-Guide-for-Beginners-by-Ranjit-Kumar.pdf
    • http://loaminoo.linkpc.net/3099095098093097/Screenplay-The-Foundations-of-Screenwriting-A-step-by-step-guide-from-concept-to-finished-script-by-Syd-Field.pdf
    • http://loaminoo.linkpc.net/1091095093097091098/Secrets-of-a-Closet-Millionaire-A-Step-By-Step-Guide-to-Financial-Freedom-by-Michele-Ashby.pdf
    • http://loaminoo.linkpc.net/4099090092090091/How-to-Keep-Your-Volkswagen-Alive-A-Manual-of-Step-by-Step-Procedures-for-the-Compleat-Idiot-by-John-Muir.pdf
    • http://loaminoo.linkpc.net/3090094094092098/The-Making-of-a-Hitter-A-Proven-and-Practical-Step-by-Step-Baseball-Guide-by-Jack-Perconte.pdf