Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b63bb50f7460cfe…

MALICIOUS

PDF

19.5 KB Created: 2019-04-30 04:07:10 +01:00 Authoring application: mPDF 5.7
MD5: a9c43923feb6835a5f7916aed4efd98c SHA-1: 57b404459f4f7508aeef4cde6768bb299ed13ecc SHA-256: 6b63bb50f7460cfe6bdaa6056a73fd151585b726e50fe81741fa7b08a0ccd94f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, forming a link farm. The ML classifier also flagged this PDF as malicious. The primary attack pattern appears to be SEO poisoning or a similar lure to drive traffic to external content. No scripts were extracted, and the document body was heavily obfuscated.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8095097096096091/You-re-The-One-That-I-Dont-Want---Kaulah-Jodoh-yang-Tak-Kuinginkan-by-Alexandra-Potter.pdf
    • http://loaminoo.linkpc.net/4095096099090/Do-You-Come-Here-Often-by-Alexandra-Potter.pdf
    • http://loaminoo.linkpc.net/3097093096092/Me-and-Mr-Darcy-by-Alexandra-Potter.pdf
    • http://loaminoo.linkpc.net/4096097096096090/What-s-New-Pussycat-by-Alexandra-Potter.pdf
    • http://loaminoo.linkpc.net/7094090093097/Calling-Romeo-by-Alexandra-Potter.pdf
    • http://loaminoo.linkpc.net/1091097095093095093/Tentokr-t-to-bude-jinak-by-Alexandra-Potter.pdf
    • http://loaminoo.linkpc.net/4097092096099092/Yin-and-Yang-Yin-and-Yang-1-by-Edward-Kendrick.pdf
    • http://loaminoo.linkpc.net/5092095097091099/Harry-Potter-and-the-Sorcerer-s-Stone---Harry-Potter-dan-Batu-Bertuah-Harry-Potter-1-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/5092095097096094/Harry-Potter-and-the-Goblet-of-Fire---Harry-Potter-dan-Piala-Api-Harry-Potter-4-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/4094094090095092/The-Love-Detective-Love-Detective-1-by-Alexandra-Potter.pdf
    • http://loaminoo.linkpc.net/1090095095092091094/Drei-Bildergeschichten-von-Beatrix-Potter-Der-b-se-Hase-Miss-Moppet-und-die-zwei-frechen-M-use-by-Beatrix-Potter.pdf
    • http://loaminoo.linkpc.net/5092095098094098/Harry-Potter-and-the-Cursed-Child---Harry-Potter-dan-Si-Anak-Terkutuk-Bagian-Satu-dan-Dua-by-John-Tiffany.pdf
    • http://loaminoo.linkpc.net/3094090099095098/Neurotica-The-Darkest-Art-of-J-K-Potter-by-J-K-Potter.pdf
    • http://loaminoo.linkpc.net/8093091093099091/Timeless-Tales-of-Beatrix-Potter-Peter-Rabbit-and-Friends-by-Beatrix-Potter.pdf
    • http://loaminoo.linkpc.net/3097098092097097/Harry-Potter-and-the-Half-Blood-Prince-Harry-Potter-6-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/1095098099093091/Harry-Potter-and-the-Cursed-Child-Harry-Potter-8-by-John-Tiffany.pdf
    • http://loaminoo.linkpc.net/5096098098098096/Harry-Potter-und-der-Gefangene-von-Askaban-German-Audio-CD-11-Compact-Discs-Edition-of-quot-Harry-Potter-and-the-Prisoner-of-Azkaban-quot-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/3098097095094/Harry-Potter-and-the-Chamber-of-Secrets-Harry-Potter-2-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/2093095097099095/Harry-Potter-and-the-Chamber-of-Secrets-Harry-Potter-2-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/2094095091099/Harry-Potter-and-the-Goblet-of-Fire-Harry-Potter-4-by-J-K-Rowling.pdf