Malicious PDF — malware analysis report

Static analysis result for SHA-256 676dc444042cf4e9…

MALICIOUS

PDF

17.9 KB Created: 2019-05-07 04:17:47 +01:00 Authoring application: mPDF 5.7
MD5: 5c0a387f4e5d0919a11bf2cdbc858cf5 SHA-1: 3918ae6bd54ef448a93a95fa69ec3696674759da SHA-256: 676dc444042cf4e92fb6096e84f8629775d67b495bbafa8466ed6a0c3d653075
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection tactic. The ML_NYX_PDF_MALICIOUS heuristic also flagged the file with high confidence. While the URLs themselves are marked as benign, the sheer volume and structure indicate a malicious intent to lure users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099091098097092/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/2090092094092097/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/1097095098096099/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/1090092095095/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/6099098099098097/Summary-of-The-Storied-Life-of-A-J-Fikry-A-Novel-by-Gabrielle-Zevin-Trivia-Quiz-for-Fans-by-Whiz-Books.pdf
    • http://loaminoo.linkpc.net/6099098099096091/The-Storied-Life-of-A-J-Fikry-A-Novel-by-Gabrielle-Zevin-Trivia-on-Books-by-Trivion-Books.pdf
    • http://loaminoo.linkpc.net/3095092095092090/The-Hole-We-re-in-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/1092096097095095/Because-It-Is-My-Blood-Birthright-2-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/2098095094094093/All-These-Things-I-ve-Done-Birthright-1-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/6099098099095098/Script-Conversations-with-Other-Women-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/2098090090092094/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/1097095099097098/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/6091097098/Young-Jane-Young-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/2092097099095092/Dan-Gets-a-Minivan-Life-at-the-Intersection-of-Dude-and-Dad-by-Dan-Zevin.pdf
    • http://loaminoo.linkpc.net/6099098097095090/Entry-Level-Life-A-Complete-Guide-to-Masquerading-as-a-Member-of-the-Real-World-by-Dan-Zevin.pdf
    • http://loaminoo.linkpc.net/4094098095098091/Snowball-Earth-The-Story-of-the-Great-Global-Catastrophe-That-Spawned-Life-as-We-Know-It-by-Gabrielle-Walker.pdf
    • http://loaminoo.linkpc.net/4094099092096093/Miracles-Now-108-Life-Changing-Tools-for-Less-Stress-More-Flow-and-Finding-Your-True-Purpose-by-Gabrielle-Bernstein.pdf
    • http://loaminoo.linkpc.net/4099095091096/Oregon-This-Storied-Land-by-William-G-Robbins.pdf
    • http://loaminoo.linkpc.net/6093099097093096/Toile-The-Storied-Fabrics-of-Europe-and-America-by-Michele-Palmer.pdf
    • http://loaminoo.linkpc.net/6099098099095097/The-Nearly-Wed-Handbook-by-Dan-Zevin.pdf