Malicious PDF — malware analysis report

Static analysis result for SHA-256 68ba152c4b307b63…

MALICIOUS

PDF

16.3 KB Created: 2019-05-04 14:29:27 +01:00 Authoring application: mPDF 5.7
MD5: 475b11488deeb6f4044ea718ff1cd2fd SHA-1: 0b09db94cbb2628623e7609c2e106f016b30d544 SHA-256: 68ba152c4b307b6343035729881e23d5a1b092567436c2620eba552cc6b9a385
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm. While the document body is heavily obfuscated, the heuristic 'PDF_SEO_LINK_FARM' indicates the primary purpose is to direct users to external PDF files. The ML classifier also flagged this as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098091094094095/Of-Darkness-and-Crowns-Goddess-Wars-2-by-Trisha-Wolfe.pdf
    • http://loaminoo.linkpc.net/1091092094090091/Destiny-s-Fire-by-Trisha-Wolfe.pdf
    • http://loaminoo.linkpc.net/4097099099094097/Cards-of-Love-Five-of-Cups-by-Trisha-Wolfe.pdf
    • http://loaminoo.linkpc.net/2097093098094097/Goddess-Test-Goddess-Interrupted-The-Goddess-Legacy-The-Goddess-Inheritance-Goddess-Test-1-3-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/3098097095098099/With-Visions-of-Red-With-Visions-of-Red-Broken-Bonds-1-3-by-Trisha-Wolfe.pdf
    • http://loaminoo.linkpc.net/3090098099097093/The-Movement-of-Crowns-Movement-of-Crowns-1-by-Nadine-C-Keels.pdf
    • http://loaminoo.linkpc.net/1090093099090092092/Eyes-Open-Sex-Domestic-Goddess-to-Sex-Goddess-by-Fiona-Chatterley.pdf
    • http://loaminoo.linkpc.net/7091094092096090/Heka-s-Blessing-A-modern-goddess-of-ancient-Egypt-Goddess-of-the-Black-Land-Book-1-by-Alexandria-Grolleau.pdf
    • http://loaminoo.linkpc.net/6094097097091/Fighting-Ruben-Wolfe-Wolfe-Brothers-2-by-Markus-Zusak.pdf
    • http://loaminoo.linkpc.net/2095092090098099/Goddess-Interrupted-Goddess-Test-2-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/3094097097095097/The-Lovestruck-Goddess-Goddess-Test-2-5B-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/3094097097095095/Goddess-of-the-Underworld-Goddess-Test-2-5C-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/3098092091093/The-Goddess-Legacy-Goddess-Test-2-5-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/4096098093093093/Wrath-of-the-Goddess-The-Goddess-s-Saga-2-by-Maria-Hammarblad.pdf
    • http://loaminoo.linkpc.net/4094091091093092/Goddess-of-the-Rose-Goddess-Summoning-Series-4-by-P-C-Cast.pdf
    • http://loaminoo.linkpc.net/4097091090092098/Goddess-of-the-Rose-Goddess-Summoning-4-by-P-C-Cast.pdf
    • http://loaminoo.linkpc.net/3098094095094/Goddess-of-Light-Goddess-Summoning-3-by-P-C-Cast.pdf
    • http://loaminoo.linkpc.net/2090097098095091/Goddess-of-Spring-Goddess-Summoning-2-by-P-C-Cast.pdf
    • http://loaminoo.linkpc.net/8099098099097093/Waking-Wolfe-Scott-Wolfe-1-by-S-L-Shelton.pdf
    • http://loaminoo.linkpc.net/4096098096097099/Oh-My-Goddess-22-Oh-My-Goddess-22-by-Kosuke-Fujishima.pdf