Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d9b8353f3911d94…

MALICIOUS

PDF

18.3 KB Created: 2019-05-01 19:05:23 +01:00 Authoring application: mPDF 5.7
MD5: 16b0b1a9db0f0d476bf6fe0d48f63b6e SHA-1: 99af156396abb160623fb4e29f7a2fc2c766f0db SHA-256: 6d9b8353f3911d940a98d900f4057fc71adf9d303d7f882a69a011dbf1b474ef
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a malicious intent to manipulate search engine results or distribute further content. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicates maliciousness. While the document body is heavily obfuscated, the presence of numerous URLs points towards a link-farming or redirection scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096091098095090/Creation-Darwin-His-Daughter-amp-Human-Evolution-by-Randal-Keynes.pdf
    • http://loaminoo.linkpc.net/4098099094092/The-Darwin-Awards-Evolution-in-Action-Darwin-Awards-1-by-Wendy-Northcutt.pdf
    • http://loaminoo.linkpc.net/9095090098095/How-Culture-Makes-Us-Human-Primate-Social-Evolution-and-the-Formation-of-Human-Societies-by-Dwight-W-Read.pdf
    • http://loaminoo.linkpc.net/8091098090098095/Discoveries-Darwin-and-the-Science-of-Evolution-by-Patrick-Tort.pdf
    • http://loaminoo.linkpc.net/3099094095097090/Saving-Darwin-How-to-Be-a-Christian-and-Believe-in-Evolution-by-Karl-W-Giberson.pdf
    • http://loaminoo.linkpc.net/5095092090093/Undeniable-Evolution-and-the-Science-of-Creation-by-Bill-Nye.pdf
    • http://loaminoo.linkpc.net/8094097094096/Undeniable-Evolution-and-the-Science-of-Creation-by-Bill-Nye.pdf
    • http://loaminoo.linkpc.net/1095092095095/Life-In-Darwin-s-Universe-Evolution-And-The-Cosmos-by-Gene-Bylinsky.pdf
    • http://loaminoo.linkpc.net/5092091092099/Darwin-s-Black-Box-The-Biochemical-Challenge-to-Evolution-by-Michael-J-Behe.pdf
    • http://loaminoo.linkpc.net/9098092094091093/On-Evolution-The-Development-of-the-Theory-of-Natural-Selection-by-Charles-Darwin.pdf
    • http://loaminoo.linkpc.net/8092098095095094/Evolution-Selected-Letters-1860-1870-by-Charles-Darwin.pdf
    • http://loaminoo.linkpc.net/4095096092090/The-New-Answers-Book-1-Over-25-Questions-on-Creation-Evolution-and-the-Bible-by-Ken-Ham.pdf
    • http://loaminoo.linkpc.net/8091090093095/The-New-Answers-Book-4-Over-30-Questions-on-Evolution-Creation-and-the-Bible-by-Ken-Ham.pdf
    • http://loaminoo.linkpc.net/4092095098095097/Darwin-s-Armada-Four-Voyages-and-the-Battle-for-the-Theory-of-Evolution-by-Iain-McCalman.pdf
    • http://loaminoo.linkpc.net/1095090098091/Darwin-s-Dangerous-Idea-Evolution-and-the-Meanings-of-Life-by-Daniel-C-Dennett.pdf
    • http://loaminoo.linkpc.net/2091095090099094/The-Darwin-Awards-Next-Evolution-Chlorinating-the-Gene-Pool-by-Wendy-Northcutt.pdf
    • http://loaminoo.linkpc.net/1099091092099091/Evolution-s-Captain-The-Dark-Fate-of-the-Man-Who-Sailed-Charles-Darwin-Around-the-World-by-Peter-Nichols.pdf
    • http://loaminoo.linkpc.net/2095097099099090/Cosmos-Creator-and-Human-Destiny-Answering-Darwin-Dawkins-and-the-New-Atheists-by-Dave-Hunt.pdf
    • http://loaminoo.linkpc.net/2096097094099/The-Evolution-of-Human-Science-by-Ted-Chiang.pdf
    • http://loaminoo.linkpc.net/4093095095098/The-Red-Queen-Sex-and-the-Evolution-of-Human-Nature-by-Matt-Ridley.pdf