Malicious PDF — malware analysis report

Static analysis result for SHA-256 67e878ea16577e9f…

MALICIOUS

PDF

15.2 KB Created: 2019-04-28 08:42:22 +01:00 Authoring application: mPDF 5.7
MD5: 6c518685f96faa4d6c6781d0ddec4364 SHA-1: b24986e4ebf76c3c638775f9cfe01e7a2acd8244 SHA-256: 67e878ea16577e9ffd4b59b9aa27f48c79ad93e639f3e77f215fce3d5a825f9f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. While the document body is heavily obfuscated, the presence of these links and the heuristic firing 'PDF_SEO_LINK_FARM' strongly suggest a malicious intent to redirect users to potentially harmful content or for SEO manipulation. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted, but the overall structure points to a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3097096094098/The-Invaders-Brotherband-Chronicles-2-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3095094095/The-Ghostfaces-Brotherband-Chronicles-6-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3098097099091093/The-Caldera-Brotherband-Chronicles-7-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3096096098094/The-Hunters-Brotherband-Chronicles-3-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/5094095095091091/Freres-D-Armes-Feuilleton-Brotherband-1-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3092097095099092/Conquest-The-Chronicles-of-the-Invaders-1-by-John-Connolly.pdf
    • http://loaminoo.linkpc.net/6095090098096094/Empire-The-Chronicles-of-the-Invaders-2-by-John-Connolly.pdf
    • http://loaminoo.linkpc.net/3092094099090090/Empire-The-Chronicles-of-the-Invaders-2-by-John-Connolly.pdf
    • http://loaminoo.linkpc.net/6095090098096098/Invaders-The-Chronowarp-Invaders-Series-Book-2-by-Vaughn-Heppner.pdf
    • http://loaminoo.linkpc.net/8093093094093097/The-Chronicles-of-Prince-ENKI-Book-One-The-A-I-Invaders-The-Dragons-amp-A-Child-by-A-E-Hazelwood.pdf
    • http://loaminoo.linkpc.net/6095090099090094/Invaders-from-the-Infinite-by-John-W-Campbell-Jr-.pdf
    • http://loaminoo.linkpc.net/9093090098097094/Die-Belagerung-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/6093090097091/The-Ruins-of-Gorlan-Ranger-s-Apprentice-1-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/1098091090094095/Halt-s-Peril-Ranger-s-Apprentice-9-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/4095098097090/Minnesota-s-Literary-Visitors-by-John-Theodore-Flanagan.pdf
    • http://loaminoo.linkpc.net/3097090094098/The-Lost-Stories-Ranger-s-Apprentice-11-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/2097092097092094/The-Burning-Bridge-Ranger-s-Apprentice-2-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3092097097091/The-Ruins-of-Gorlan-Ranger-s-Apprentice-1-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3094091097094/The-Emperor-of-Nihon-Ja-Ranger-s-Apprentice-10-by-John-Flanagan.pdf
    • http://loaminoo.linkpc.net/3093099099091/The-Siege-of-Macindaw-Ranger-s-Apprentice-6-by-John-Flanagan.pdf