Malicious PDF — malware analysis report

Static analysis result for SHA-256 6e7a13537bf64958…

MALICIOUS

PDF

26.5 KB Created: 2019-05-04 12:38:25 +01:00 Authoring application: mPDF 5.7
MD5: 5f42a22eaea1d2c9a327381780c22b73 SHA-1: 405e4d3b29c7ab125edd7cfd9f0725da2486c46f SHA-256: 6e7a13537bf649581231d8c1469dc7d70d028c2eb5cb64a9b9d04f51e5adb949
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous URLs suggests an attempt to direct users to potentially malicious content or for SEO manipulation. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8091093095099094/The-Triumphant-Cat-An-Anthology-of-Verse-Prose-amp-Pictures-Gathered-from-the-Ancient-amp-Modern-Authors-by-Marmaduke-Skidmore.pdf
    • http://loaminoo.linkpc.net/3091097099092092/Cats-An-anthology-of-verse-amp-prose-by-Emily-Tibbs.pdf
    • http://loaminoo.linkpc.net/1091097090092092096/Voices-from-Finland-An-Anthology-of-Finlands-Verse-and-Prose-by-Elli-Tompuri.pdf
    • http://loaminoo.linkpc.net/5097097090095091/The-Complete-Fairy-Tales-in-Verse-and-Prose-L-Integrale-des-Contes-en-vers-et-en-prose-A-Dual-Language-Book-by-Charles-Perrault.pdf
    • http://loaminoo.linkpc.net/6094090090098093/THE-DIVINE-COMEDY-ULTIMATE---4-Famous-Translations---Dante-s-Inferno-Purgatorio-Purgatory-and-Paradiso-Paradise-in-verse-prose-modern-English---Longfellow-Cary-Norton-Langdon-PLUS-BIOGRAPHY-by-Dante-Alighieri.pdf
    • http://loaminoo.linkpc.net/3096093095096093/Baudelaire-Rimbaud-Verlaine-Selected-Verse-and-Prose-Poems-by-Joseph-M-Bernstein.pdf
    • http://loaminoo.linkpc.net/4095099099090093/The-Stuffed-Owl-An-Anthology-of-Bad-Verse-by-D-B-Wyndham-Lewis.pdf
    • http://loaminoo.linkpc.net/3095096099096091/LOL-Romantic-Comedy-Anthology---Volume-2---Even-More-All-New-Romance-Stories-by-Bestselling-Authors-LOL-2-by-Rachel-Schurig.pdf
    • http://loaminoo.linkpc.net/9094098092095093/Capturing-Chinese-Stories-Prose-and-Poems-by-Revolutionary-Chinese-Authors-Including-Lu-Xun-Hu-Shi-Zhu-Ziqing-Zhou-Zuoren-and-Lin-Yutang-by-Lu-Xun.pdf
    • http://loaminoo.linkpc.net/1091095097099097093/The-Prose-Poem-An-International-Anthology-by-Michael-Benedikt.pdf
    • http://loaminoo.linkpc.net/6093095096090090/The-Decameron-of-Giovanni-Boccacci-Now-First-Completely-Done-Into-Engl-Prose-and-Verse-by-J-Payne-by-Giovanni-Boccaccio.pdf
    • http://loaminoo.linkpc.net/2093098092094097/Poetry-for-Cats-The-Definitive-Anthology-of-Distinguished-Feline-Verse-by-Henry-N-Beard.pdf
    • http://loaminoo.linkpc.net/7096094096096097/Russian-Love-Stories-An-Anthology-of-Contemporary-Prose-by-Nadya-L-Peterson.pdf
    • http://loaminoo.linkpc.net/5092093091099099/Venom-in-Verse-Aristophanes-in-Modern-Greece-by-Gonda-A-H-Van-Steen.pdf
    • http://loaminoo.linkpc.net/3099094094091094/Reflections-on-a-Gift-of-Watermelon-Pickle-And-Other-Modern-Verse-by-Stephen-Dunning.pdf
    • http://loaminoo.linkpc.net/4099097091094091/True-Heroes-A-Treasury-of-Modern-day-Fairy-Tales-Written-by-Best-Selling-Authors-by-Jonathan-Diaz.pdf
    • http://loaminoo.linkpc.net/5096095096090097/History-in-Images-Pictures-and-Public-Space-in-Modern-China-by-Christian-Henriot.pdf
    • http://loaminoo.linkpc.net/2097098091092091/The-Ramayana-A-Shortened-Modern-Prose-Version-of-the-Indian-Epic-by-R-K-Narayan.pdf
    • http://loaminoo.linkpc.net/8091093096098098/The-Life-of-Marmaduke-Rawdon-of-York-Or-Marmaduke-Rawdon-the-Second-of-That-Name-by-Robert-Davies.pdf
    • http://loaminoo.linkpc.net/1091096090096091098/Watersong-Circle-A-Diary-of-Flowers-An-Anthology-of-Flowers-and-Verse---Second-Edition-by-Tuttle-Publishing.pdf