Malicious PDF — malware analysis report

Static analysis result for SHA-256 68bcb9db9b322b0e…

MALICIOUS

PDF

18.2 KB Created: 2019-05-02 01:31:08 +01:00 Authoring application: mPDF 5.7
MD5: 9f4a3c6b3783f152f4c41c7275055c95 SHA-1: d6f56f2758b3da3211911ea44059c8ca3b5e8437 SHA-256: 68bcb9db9b322b0e32535f04cb957eb34442ac526071d6566db353b65bdfbca6
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting the PDF is designed to redirect users to a large number of other PDF files. While the specific intent of these linked PDFs is unclear, the sheer volume and the nature of the heuristic suggest a malicious SEO poisoning or content hosting scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090097091090096090/Tess-Gerritsen-Collection-The-Mephisto-Club-Call-After-Midnight-In-Their-Footsteps-Gravity-Whistleblower-Under-The-Knife-Stolen-Presumed-Guilty-Keeper-Of-The-Bride-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/1090097091091092095/A-Rizzoli-and-Isles-Series-Collection-5-Books-Set-By-Tess-Gerritsen-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/1090097090099090095/Interview-with-Tess-Gerritsen-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/8098095095094093/Das-L-cheln-in-deinen-Augen-by-Julia-Arden.pdf
    • http://loaminoo.linkpc.net/1091095097093096094/Das-B-se-in-deinen-Augen-by-Jenny-Blackhurst.pdf
    • http://loaminoo.linkpc.net/1091095097094094092/Sommer-in-deinen-Augen-by-Sara-Belin.pdf
    • http://loaminoo.linkpc.net/1091095097093096093/Mein-Gl-ck-in-deinen-Augen-by-Cardeno-C-.pdf
    • http://loaminoo.linkpc.net/1090097091091093096/LIST-SERIES-TESS-GERRITSEN-SERIES-READING-ORDER-TRAVISTOCK-FAMILY-BOOKS-RIZZOLI-amp-ISLES-BOOKS-RIZZOLI-amp-ISLES-SHORT-STORIES-STANDALONE-NOVELS-BY-TESS-GERRITSEN-by-List-Series.pdf
    • http://loaminoo.linkpc.net/6095095093093091/In-deinen-Augen-The-Wolves-of-Mercy-Falls-3-by-Maggie-Stiefvater.pdf
    • http://loaminoo.linkpc.net/1091095097092098096/Nach-dem-Sommer-Ruht-das-Licht-In-deinen-Augen-The-Wolves-of-Mercy-Falls-1-3-by-Maggie-Stiefvater.pdf
    • http://loaminoo.linkpc.net/1093092091096093/Die-Again-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/6099093093090099/Never-Say-Die-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/3091097091096097/Whistleblower-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/4090096099092/Gravity-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/4097096096096098/Bloodstream-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/4090096098095/Harvest-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/1099090095093091/The-Bone-Garden-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/9098099093/Die-Again-Rizzoli-amp-Isles-11-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/1090097091090093092/Under-the-Knife-Whistleblower-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/4090094099095/The-Bone-Garden-by-Tess-Gerritsen.pdf