Malicious PDF — malware analysis report

Static analysis result for SHA-256 6efa112e2788d24c…

MALICIOUS

PDF

19.2 KB Created: 2019-05-01 20:09:03 +01:00 Authoring application: mPDF 5.7
MD5: 216fea623f23173c2ea62ca1b5750404 SHA-1: bb028130c0a64ca8b9169393bea20e02b18d3916 SHA-256: 6efa112e2788d24c13f2c72ee81a7fbac0aef017302a5ecfe3afea99d09ba5eb
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to host malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a dropper. While no scripts were directly extracted, the embedded URLs suggest a potential for downloading further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7090426-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7090426-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3090096099096090/The-Immigrant-and-the-Golden-Coin-Mike-McBride-Series-3-by-Dorothy-May-Mercer.pdf
    • http://loaminoo.linkpc.net/1097093093094092/The-Immigrant-and-the-Golden-Coin-Book-Three-the-McBride-Series-by-Dorothy-May-Mercer.pdf
    • http://loaminoo.linkpc.net/1098090098092095/Alaska-and-Back-With-Dave-and-Dorothy-by-Dorothy-May-Mercer.pdf
    • http://loaminoo.linkpc.net/3090097098095097/Italian-Immigrant-Cooking-Immigrant-Cookbook-Series-Bk-1-by-Elodia-Rigante.pdf
    • http://loaminoo.linkpc.net/1097093093094096/Leon-and-Esther-by-Dorothy-May-Mercer.pdf
    • http://loaminoo.linkpc.net/5092092094098/Girl-on-the-Golden-Coin-by-Marci-Jefferson.pdf
    • http://loaminoo.linkpc.net/2097094096098093/How-to-Write-Great-Dialog-Your-Book-Needs-This-by-Dorothy-May-Mercer.pdf
    • http://loaminoo.linkpc.net/1090099097094092093/Coordination-Organizations-Institutions-and-Norms-in-Agent-Systems-III-Coin-2007-International-Workshops-Coin-aamas-2007-Honolulu-Hi-USA-May-2007-Coin-mallow-2007-Durham-UK-September-2007-Revised-Selected-Papers-by-Jaime-Simao-Sichman.pdf
    • http://loaminoo.linkpc.net/3093097092096091/Keeper-of-Coin-The-Carty-Sisters-Series-Book-1-by-Mary-Kay-Tuberty.pdf
    • http://loaminoo.linkpc.net/1090092095099099/Fangtastic-My-Sister-the-Vampire-Series-2-by-Sienna-Mercer.pdf
    • http://loaminoo.linkpc.net/1090092092098091/Re-Vamped-My-Sister-the-Vampire-Series-3-by-Sienna-Mercer.pdf
    • http://loaminoo.linkpc.net/2090091096098097/Quantum-Coin-Coin-2-by-E-C-Myers.pdf
    • http://loaminoo.linkpc.net/2094096097095090/The-Christmas-Angel-The-McBride-Series-by-Tina-Russo.pdf
    • http://loaminoo.linkpc.net/5091099096099099/Mercer-Magic-Roeblings-Kusers-The-Mercer-Automobile-Company-and-America-s-First-Sports-Car-by-Clifford-W-Zink.pdf
    • http://loaminoo.linkpc.net/2096095098093092/The-Golden-Crown-Series-Golden-Crown-Series-1-3-by-Rue-Volley.pdf
    • http://loaminoo.linkpc.net/9091099090097098/The-Sword-of-Laban-and-the-Tree-of-Life-The-Golden-Plates-1-by-Mike-Allred.pdf
    • http://loaminoo.linkpc.net/2093091095097098/Mrs-Pollifax-and-the-Golden-Triangle-Mrs-Pollifax-8-by-Dorothy-Gilman.pdf
    • http://loaminoo.linkpc.net/3097091094096092/Stars-Over-Buffalo-Erie-Canal-Cousins-Series---Book-5-by-Dorothy-Stacy.pdf
    • http://loaminoo.linkpc.net/1093093090090095/The-Mike-Bowditch-Series-Books-1-3-by-Paul-Doiron.pdf
    • http://loaminoo.linkpc.net/3090090098092094/Valiant-The-Adventures-of-Merlin-Series-1-2-by-Mike-Tucker.pdf