Malicious PDF — malware analysis report

Static analysis result for SHA-256 6558cf970f18143b…

MALICIOUS

PDF

25.7 KB Created: 2019-05-02 02:10:37 +01:00 Authoring application: mPDF 5.7
MD5: 1b77dc17f09b958de9b235d051c6e5f5 SHA-1: 1a6adfc9b814000874dbbeaa55cb9c8d193abd09 SHA-256: 6558cf970f18143b8419f56f9334e6438d5e24cf690627be1998ca37f90a6557
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links are presented in a way that suggests they are book titles, likely to trick users into clicking them. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099094092093094/Would-You-Rather-A-Memoir-of-Growing-Up-and-Coming-Out-by-Katie-Heaney.pdf
    • http://loaminoo.linkpc.net/7095093095092099/Bilateral-Relations-of-Guyana-Guyana-Russia-Relations-Guyana---United-States-Relations-Brazil-Guyana-Relations-Guyana-Venezuela-Relations-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/7096093090091094/The-PR-Masterclass-How-to-Develop-a-Public-Relations-Strategy-That-Works-by-Alex-Singleton.pdf
    • http://loaminoo.linkpc.net/8090095099097097/Praxishandbuch-Augmented-Reality-f-r-Marketing-Medien-und-Public-Relations-by-Dirk-Schart.pdf
    • http://loaminoo.linkpc.net/1090093097091092099/Strategic-Writing-Multimedia-Writing-for-Public-Relations-Advertising-and-More-by-Charles-Marsh.pdf
    • http://loaminoo.linkpc.net/1091098098092099095/Politiker---Parlamente---Public-Relations-Thomas-Manns-Roman-Koenigliche-Hoheit-ALS-Spiegel-Des-Aktuellen-Politischen-Geschehens-Ein-Literarisch-Politischer-Essay-by-Joachim-Rickes.pdf
    • http://loaminoo.linkpc.net/9096096093090090/Communication-Information-Theory-Public-Relations-Sign-Damaging-Quotation-Telemetry-Data-Storage-Device-Superluminal-Communication-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/1091093092094094096/Public-Economics-and-Public-Choice-Contributions-in-Honor-of-Charles-B-Blankart-by-Pio-Baake.pdf
    • http://loaminoo.linkpc.net/7092095091092096/Going-Public-Minimize-Fear-Maximize-Success-Master-Public-Speaking-by-Karen-a-Pelot.pdf
    • http://loaminoo.linkpc.net/1090097093091091099/Public-Attitudes-Toward-Family-Policies-in-Europe-Linking-Institutional-Context-and-Public-Opinion-by-Monika-Mischke.pdf
    • http://loaminoo.linkpc.net/4095099090093091/Door-Into-The-Dark-by-Seamus-Heaney.pdf
    • http://loaminoo.linkpc.net/4091099095097/The-Spirit-Level-by-Seamus-Heaney.pdf
    • http://loaminoo.linkpc.net/4095098092095/Death-of-a-Naturalist-by-Seamus-Heaney.pdf
    • http://loaminoo.linkpc.net/1090095095090093/District-and-Circle-by-Seamus-Heaney.pdf
    • http://loaminoo.linkpc.net/3093091091092093/Seeing-Things-Poems-by-Seamus-Heaney.pdf
    • http://loaminoo.linkpc.net/9098094095/Chocolate-Covered-Katie-Over-80-Delicious-Recipes-That-Are-Secretly-Good-for-You-by-Katie-Higgins.pdf
    • http://loaminoo.linkpc.net/3097096092095098/Katie-s-Hellion-amp-Katie-s-Hope-Rhyn-Trilogy-1-2-by-Lizzy-Ford.pdf
    • http://loaminoo.linkpc.net/6097094094095092/Crediting-Poetry-The-Nobel-Lecture-by-Seamus-Heaney.pdf
    • http://loaminoo.linkpc.net/4099091096098092/The-Oxford-Anthology-of-English-Poetry-Vol-2-Blake-to-Heaney-by-John-Wain.pdf
    • http://loaminoo.linkpc.net/6095096093097091/Investing-in-America-s-Infrastructure-Short-And-Long-Term-Strategies-Hearings-Before-the-Subcommittee-on-Economic-Development-of-the-Committee-on-Public-Works-and-Transportation-House-of-Representatives-One-Hundred-Third-Congress-First-Session-Janua-by-Public-Works-and-Transportation-Comm.pdf