Malicious PDF — malware analysis report

Static analysis result for SHA-256 6be2e80ce71a3950…

MALICIOUS

PDF

17.9 KB Created: 2019-04-30 06:41:03 +01:00 Authoring application: mPDF 5.7
MD5: e4857509884862c452820d437cdea009 SHA-1: 9a30b3f571dfd10cfa76f347a0da38b40db4f171 SHA-256: 6be2e80ce71a395091b291d4e41889bd477a96572e2a4b39a35ade955d3b8330
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, forming a link farm hosted on a dynamic DNS domain. This behavior is indicative of a phishing or redirection scheme, likely intended to lead users to malicious content or further stages of an attack. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9094090098095096/Panzer-Gunner-From-My-Native-Canada-to-the-German-Osfront-and-Back-In-Action-with-25th-Panzer-Regiment-7th-Panzer-Division-1944-45-by-Bruno-Friesen.pdf
    • http://loaminoo.linkpc.net/9094090098099099/Panzer-Operations-Germany-s-Panzer-Group-3-During-the-Invasion-of-Russia-1941-by-Hermann-Hoth.pdf
    • http://loaminoo.linkpc.net/8099099091092092/Panzer-Wedge-Volume-Two-The-German-3rd-Panzer-Division-and-Barbarossa-s-Failure-at-the-Gates-of-Moscow-by-Fritz-Lucke.pdf
    • http://loaminoo.linkpc.net/1091098091094/He-Calls-Her-Doc-Harlequin-Superromance-1561-by-Mary-Brady.pdf
    • http://loaminoo.linkpc.net/2098094097095092/First-Light-Brady-Coyne-19-Brady-Coyne-J-W-Jackson-1-by-Philip-R-Craig.pdf
    • http://loaminoo.linkpc.net/9094090098095092/Girls-Und-Panzer-vol-1-by-Girls-und-Panzer-Projekt.pdf
    • http://loaminoo.linkpc.net/9094090099090096/Girls-Und-Panzer-Vol-4-by-Girls-und-Panzer-Projekt.pdf
    • http://loaminoo.linkpc.net/2092093098094099/The-Lease-by-Mathew-Henderson.pdf
    • http://loaminoo.linkpc.net/4097097097095098/Spire-by-Mathew-Ferguson.pdf
    • http://loaminoo.linkpc.net/1091096092098090098/Mathew-s-Tale-by-Quintin-Jardine.pdf
    • http://loaminoo.linkpc.net/3096094096094093/Gula-The-Oswald-Witches-3-by-Mathew-Ortiz.pdf
    • http://loaminoo.linkpc.net/3092097093090091/Day-Breaks-Dire-Calls-1-by-Mathew-Reuther.pdf
    • http://loaminoo.linkpc.net/6096095093094094/Adeste-Fideles-And-Beware-of-the-Dog-by-Mathew-Hannigan.pdf
    • http://loaminoo.linkpc.net/4091091093090094/Desdemona-Darkly-When-Mickey-met-Hugh-by-Mathew-Ortiz.pdf
    • http://loaminoo.linkpc.net/9094096094096/Chinaman-The-Legend-of-Pradeep-Mathew-by-Shehan-Karunatilaka.pdf
    • http://loaminoo.linkpc.net/9094090099091093/Panzer-38-by-Steven-J-Zaloga.pdf
    • http://loaminoo.linkpc.net/1097098099099096/ATTRACTING-FOR-OTHERS-A-NEVER-BEFORE-REVEALED-SECRET-POWER-TO-THE-LAW-OF-ATTRACTION-by-Mathew-Dixon.pdf
    • http://loaminoo.linkpc.net/2097092091096096/Slimed-An-Oral-History-of-Nickelodeon-s-Golden-Age-by-Mathew-Klickstein.pdf
    • http://loaminoo.linkpc.net/9094091091097097/Panzer-Pzkpfw-III-by-Terry-Gander.pdf
    • http://loaminoo.linkpc.net/9094091090097092/Panzer-Modelling-by-Tony-Greenland.pdf