Malicious PDF — malware analysis report

Static analysis result for SHA-256 64f0a3288b3ad5aa…

MALICIOUS

PDF

14.7 KB Created: 2019-05-07 03:47:39 +01:00 Authoring application: mPDF 5.7
MD5: 673bef8251838e6a6d2035f65419a063 SHA-1: 3001574721a2576f46c79d9df63526ffda8532f6 SHA-256: 64f0a3288b3ad5aa59a4b295eff5a22f76e6af96decb6532c59740b9238be3a7
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. These URLs point to what appear to be book titles, suggesting a lure to trick users into downloading potentially malicious PDF files. The ML classifier strongly indicates maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of numerous external links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3097092095093092/Body-Swap-by-Sylvia-McNicoll.pdf
    • http://loaminoo.linkpc.net/3099097092091094/The-Snake-Mistake-Mystery-The-Great-Mistake-Mysteries-3-by-Sylvia-McNicoll.pdf
    • http://loaminoo.linkpc.net/3091096091093099/Beauty-Returns-Beauty-3-by-Sylvia-McNicoll.pdf
    • http://loaminoo.linkpc.net/1094098093090095/Sylvia-Day-Crossfire-Series-4-Volume-Boxed-Set-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/1098096091093096/Highway-Revenge-Revenge-1-by-Nadine-Millard.pdf
    • http://loaminoo.linkpc.net/3099091098099092/Revenge-Volume-2-Revenge-2-by-J-J-Knight.pdf
    • http://loaminoo.linkpc.net/7093090099092/The-Element-of-Lavishness-Letters-of-William-Maxwell-and-Sylvia-Townsend-Warner-1938-1978-by-Sylvia-Townsend-Warner.pdf
    • http://loaminoo.linkpc.net/3096090090098/The-Unabridged-Journals-of-Sylvia-Plath-by-Sylvia-Plath.pdf
    • http://loaminoo.linkpc.net/2092093092095091/Sylvia-Browne-s-Lessons-for-Life-by-Sylvia-Browne.pdf
    • http://loaminoo.linkpc.net/2097090099090098/Revenge-Revenge-1-by-J-J-Knight.pdf
    • http://loaminoo.linkpc.net/1092090091096090/Revenge-Of-The-Wolf-Revenge-Of-The-Wolf-1-by-Skyler-Patterson.pdf
    • http://loaminoo.linkpc.net/1097096091093099/Echo-s-Revenge-Echo-s-Revenge-1-by-Sean-Austin.pdf
    • http://loaminoo.linkpc.net/1093093092099/Rapunzel-s-Revenge-Rapunzel-s-Revenge-1-by-Shannon-Hale.pdf
    • http://loaminoo.linkpc.net/9094098094091094/Masamune-kun-no-Revenge-Vol-06-Masamune-kun-no-Revenge-6-by-Hazuki-Takeoka.pdf
    • http://loaminoo.linkpc.net/9098094092090099/The-Diaries-of-Sylvia-Townsend-Warner-by-Sylvia-Townsend-Warner.pdf
    • http://loaminoo.linkpc.net/2096096094095090/Spellbound-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/3099090093091097/Ask-For-It-Georgian-1-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/9096097099096093/Afterburn-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/6091091096091092/Bared-to-You-by-Sylvia-Day.pdf
    • http://loaminoo.linkpc.net/1093091099092091/One-with-You-Crossfire-5-by-Sylvia-Day.pdf