Malicious PDF — malware analysis report

Static analysis result for SHA-256 6aa1db569b9d3db3…

MALICIOUS

PDF

20.9 KB Created: 2019-05-06 16:40:29 +01:00 Authoring application: mPDF 5.7
MD5: 515f5550eeeb9cfbbf928e978fead291 SHA-1: 7f3db70f1fdcfe824e9b3ac8da73e49b236d38ae SHA-256: 6aa1db569b9d3db3f9437979f78ef2234488c9560fa0eb3d9992d51d1e2304d4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. This is indicative of a phishing or redirection attempt, likely to distribute further malicious content or lead users to scam websites. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090094095098098091/Articles-on-Skulduggery-Pleasant-Books-Including-Skulduggery-Pleasant-List-of-Skulduggery-Pleasant-Characters-Skulduggery-Pleasant-Playing-with-Fire-Skulduggery-Pleasant-The-Faceless-Ones-Skulduggery-Pleasant-Series-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/3090098092099091/What-to-Cook-and-How-to-Cook-It-by-Jane-Hornby.pdf
    • http://loaminoo.linkpc.net/9099099095098/Standing-Up-with-Ga-axsta-las-Jane-Constance-Cook-and-the-Politics-of-Memory-Church-and-Custom-by-Leslie-A-Robertson.pdf
    • http://loaminoo.linkpc.net/2090097099097091/Skulduggery-Pleasant-1-5-Skulduggery-Pleasant-1-5-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1090094095098097099/Skulduggery-Pleasant-4-6-Skulduggery-Pleasant-4-6-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/4093090091097/Skulduggery-Pleasant-Skulduggery-Pleasant-1-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1090094095098098090/Skulduggery-Pleasant-1-3-Skulduggery-Pleasant-1-3-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1091098097099096095/Im-Netz-des-Wachtturms---ein-Vater-k-mpft-um-seine-Kinder-Will-Cook-und-die-Wachtturmgesellschaft-by-Will-Cook.pdf
    • http://loaminoo.linkpc.net/3091091091090094/How-to-Cook-Everything-Fast-A-Better-Way-to-Cook-Great-Food-by-Mark-Bittman.pdf
    • http://loaminoo.linkpc.net/2096097096092093/How-to-Cook-Without-a-Book-Recipes-and-Techniques-Every-Cook-Should-Know-by-Heart-by-Pam-Anderson.pdf
    • http://loaminoo.linkpc.net/4093098095097092/The-Journals-of-Captain-Cook-by-James-Cook.pdf
    • http://loaminoo.linkpc.net/2096091091098095/Tragically-I-Was-an-Only-Twin-The-Complete-Peter-Cook-by-Peter-Cook.pdf
    • http://loaminoo.linkpc.net/7097090091095097/The-Voyages-of-Captain-James-Cook-The-Illustrated-Accounts-of-Three-Epic-Pacific-Voyages-by-James-Cook.pdf
    • http://loaminoo.linkpc.net/1090096099092099092/Mr-Pleasant-by-Jim-Ray-Daniels.pdf
    • http://loaminoo.linkpc.net/9090097096099092/Pleasant-Fieldmouse-by-Jan-Wahl.pdf
    • http://loaminoo.linkpc.net/3096091099091098/Senorita-Sin-by-Pleasant-Gehman.pdf
    • http://loaminoo.linkpc.net/3096091099091095/Princess-of-Hollywood-by-Pleasant-Gehman.pdf
    • http://loaminoo.linkpc.net/1090095091092094/Just-the-Way-You-Are-Pleasant-Gap-Romance-1-by-Pepper-D-Basham.pdf
    • http://loaminoo.linkpc.net/1090096099091093097/The-Pleasant-Light-Of-Day-by-Philip-Ceallaigh.pdf
    • http://loaminoo.linkpc.net/1090096099092098099/Gardening-Essentials-by-Barbara-Pleasant.pdf