Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d3cf637721044ba…

MALICIOUS

PDF

21.2 KB Created: 2019-05-01 19:56:42 +01:00 Authoring application: mPDF 5.7
MD5: dfc3cfb720e7dd57d918c4f48edd9645 SHA-1: eaabcfe4952cbd11e0ad990eb16326a63540965e SHA-256: 6d3cf637721044baf10e3ebdd1f85746605b19f769f8d8ef29dd8b2a978faa5d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were labeled as confirmed benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096091095092091/The-Butterfly-Mosque-A-Young-American-Woman-s-Journey-to-Love-and-Islam-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/7097098093099099/The-Islam-Quintet-Shadows-of-the-Pomegranate-Tree-The-Book-of-Saladin-The-Stone-Woman-A-Sultan-in-Palermo-and-Night-of-the-Golden-Butterfly-by-Tariq-Ali.pdf
    • http://loaminoo.linkpc.net/4099092093092/I-Am-Hutterite-The-Fascinating-True-Story-of-a-Young-Woman-s-Journey-to-Reclaim-Her-Heritage-by-Mary-Ann-Kirkby.pdf
    • http://loaminoo.linkpc.net/4094099099097090/Let-s-Talk-About-Love-A-Journey-to-the-End-of-Taste-by-Carl-Wilson.pdf
    • http://loaminoo.linkpc.net/3098099098096090/The-Spinster-s-Vow-A-Spicy-Retelling-of-Mrs-Darcy-s-Journey-to-Love-by-Enid-Wilson.pdf
    • http://loaminoo.linkpc.net/6090095095097090/Buildings-and-Structures-in-Nablus-Mosques-in-Nablus-Jacob-s-Well-Al-Khadra-Mosque-An-Najah-National-University-Great-Mosque-of-Nablus-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/4092091099095090/Threading-My-Prayer-Rug-One-Woman-s-Journey-from-Pakistani-Muslim-to-American-Muslim-by-Sabeeha-Rehman.pdf
    • http://loaminoo.linkpc.net/2098096093093/Journey-Into-Light-A-Story-of-a-Woman-s-Courage-to-Heal-Love-and-Forgive-by-Gayle-Rose-Martinez.pdf
    • http://loaminoo.linkpc.net/2092091092/Ms-Marvel-Vol-4-Last-Days-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/6092094/Ms-Marvel-Vol-2-Generation-Why-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/7090093091/Ms-Marvel-Vol-8-Mecca-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/2095098093090/Alif-the-Unseen-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/3097092098093099/A-Force-Warzones-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/8095094094095096/Ms-Marvel-2014-2015-13-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/1090097098094097099/Ms-Marvel-2014-2015-6-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/3096092096/Ms-Marvel-Vol-5-Super-Famous-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/1090097098095092094/Ms-Marvel-2014-2015-9-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/1099093091097091/Vixen-Return-of-the-Lion-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/1099093090099091/Ms-Marvel-2014-2015-2-by-G-Willow-Wilson.pdf
    • http://loaminoo.linkpc.net/1091091097092091099/Unveiled-How-an-American-Woman-Found-Her-Way-Through-Politics-Love-and-Obedience-in-the-Middle-East-by-Deborah-Kanafani.pdf