Malicious PDF — malware analysis report

Static analysis result for SHA-256 6f94e26fa43cc128…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 02:53:23 +01:00 Authoring application: mPDF 5.7
MD5: 0cd0c8d684dfb68d7bb010d1b8078516 SHA-1: f4e727f67199d1abb35c6ffb47effe795eb99cfa SHA-256: 6f94e26fa43cc12847c31b9cee5041d16524d3ee406efb2e5ec19443d33cdb2e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, forming a link farm. While the document body is corrupted, the heuristic `PDF_SEO_LINK_FARM` indicates the primary purpose is to direct users to external PDF files. The ML classifier also flagged this PDF as malicious. The specific URLs suggest a potential attempt to distribute further malicious content or engage in SEO-based abuse.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099090091091094/One-and-Only-The-Freedom-of-Having-an-Only-Child-and-the-Joy-of-Being-One-by-Lauren-Sandler.pdf
    • http://loaminoo.linkpc.net/3098090092098098/The-Princess-and-the-Pea-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/1096094093098090/that-pesky-rat-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/2097095098096/I-Will-Never-Not-Ever-Eat-a-Tomato-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/2095093092098099/I-Am-Not-Sleepy-and-I-Will-Not-Go-to-Bed-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/4098090098092095/Clarice-Bean-That-s-Me-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/2096098099093091/Who-s-Afraid-of-the-Big-Bad-Book-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/4091090098092098/But-Excuse-Me-That-Is-My-Book-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/4094094098092/Blink-and-You-Die-Ruby-Redfort-6-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/7090093093092099/Maude-The-Not-So-Noticeable-Shrimpton-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/5094098093099/Catch-Your-Death-Ruby-Redfort-3-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/1090097093096090099/Clarice-Bean-Guess-Who-s-Babysitting-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/7096091091099/Pick-Your-Poison-Ruby-Redfort-5-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/6095095097095093/Lauren-Daigle---Look-Up-Child-by-Lauren-Daigle.pdf
    • http://loaminoo.linkpc.net/4091096093093096/Kiddie-Cocktails-by-Stuart-Sandler.pdf
    • http://loaminoo.linkpc.net/1090098095097094096/As-New-Englanders-Played-by-Martin-W-Sandler.pdf
    • http://loaminoo.linkpc.net/7098099095094/Hang-in-There-Bozo-The-Ruby-Redfort-Emergency-Survival-Guide-for-Some-Tricky-Predicaments-Ruby-Redfort-0-5-by-Lauren-Child.pdf
    • http://loaminoo.linkpc.net/1091091098099099090/Secret-Subway-The-Fascinating-Tale-of-an-Amazing-Feat-of-Engineering-by-Martin-W-Sandler.pdf
    • http://loaminoo.linkpc.net/3090097091092/Freedom-Volume-2-Freedom-In-The-Modern-World-by-Orlando-Patterson.pdf
    • http://loaminoo.linkpc.net/1094095096092093/Hell-Fire-amp-Freedom-Fighting-for-Freedom-1-by-Shannon-Callahan.pdf