Malicious PDF — malware analysis report

Static analysis result for SHA-256 6af9267e4a682576…

MALICIOUS

PDF

16.9 KB Created: 2019-04-30 02:44:51 +01:00 Authoring application: mPDF 5.7
MD5: 5bef6bb74681d4831f6556fcbc6070f7 SHA-1: 842acd6f692296f75939d25f3892ce39b419a923 SHA-256: 6af9267e4a682576b0cf2b41ef928bc0a24401ca319a8b104069fac72a20cc72
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection scheme. While the URLs themselves are currently marked as benign, the sheer volume and the ML classifier's high confidence score indicate a malicious intent, likely to lure users to malicious sites or phishing pages. The attack pattern is consistent with a spearphishing attachment used to distribute malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090096090090097/Gray-Back-Bad-Bear-Gray-Back-Bears-1-by-T-S-Joyce.pdf
    • http://loaminoo.linkpc.net/4092094093097/Come-Back-to-Me-Come-Back-to-Me-1-by-Mila-Gray.pdf
    • http://loaminoo.linkpc.net/4099098098096091/Run-Away-With-Me-Come-Back-To-Me-3-by-Mila-Gray.pdf
    • http://loaminoo.linkpc.net/4097095096094098/Stay-With-Me-Come-Back-to-Me-2-by-Mila-Gray.pdf
    • http://loaminoo.linkpc.net/9096094090095093/Back-Pain-Get-Your-Back-BACK---Your-Self-Help-Guide-on-How-to-Treat-Back-Pain-Naturally-and-Without-Drugs-Understanding-the-Anatomy-of-the-Back-Holistic-Pain-Holistic-Healing-Back-Pain-Book-1-by-Joschi-Schwarz.pdf
    • http://loaminoo.linkpc.net/3099094093098098/Back-When-You-Were-Easier-to-Love-by-Emily-Wing-Smith.pdf
    • http://loaminoo.linkpc.net/2099092093091095/Mathematical-Sorcery-by-Calvin-C-Clawson.pdf
    • http://loaminoo.linkpc.net/7099094096094099/The-Crown-s-Vengeance-by-Andrew-Clawson.pdf
    • http://loaminoo.linkpc.net/4094098095097097/Mathematical-Mysteries-The-Beauty-and-Magic-of-Numbers-by-Calvin-C-Clawson.pdf
    • http://loaminoo.linkpc.net/6097096094099096/The-Portrait-of-Dorian-Gray-Teacher-s-Book-by-Elizabeth-Gray.pdf
    • http://loaminoo.linkpc.net/3094099093095096/Back-To-Back-Behind-Your-Back-2-by-Chelsea-M-Cameron.pdf
    • http://loaminoo.linkpc.net/4095097097099096/Brothers-Blue-and-Gray-by-Ellen-Gray-Massey.pdf
    • http://loaminoo.linkpc.net/6097099094096091/Gray-Vengeance-Tom-Gray-5-by-Alan-McDermott.pdf
    • http://loaminoo.linkpc.net/5094090091095099/Gray-Justice-Tom-Gray-1-by-Alan-McDermott.pdf
    • http://loaminoo.linkpc.net/1097094092097093/The-Legendary-Life-of-Bee-Ho-Gray-by-Clark-Gray.pdf
    • http://loaminoo.linkpc.net/3095098095092097/Gray-Resurrection-Tom-Gray-2-by-Alan-McDermott.pdf
    • http://loaminoo.linkpc.net/6097099094096090/Gray-Salvation-Tom-Gray-6-by-Alan-McDermott.pdf
    • http://loaminoo.linkpc.net/3092099096092097/Breaking-Back-How-I-Lost-Everything-and-Won-Back-My-Life-by-James-Blake.pdf
    • http://loaminoo.linkpc.net/4093096097092097/Breaking-Back-How-I-Lost-Everything-and-Won-Back-My-Life-by-James-Blake.pdf
    • http://loaminoo.linkpc.net/5099096096096094/Back-on-Track-Shifting-Back-to-Grace-by-Ru-Dela-Torre.pdf