Malicious PDF — malware analysis report

Static analysis result for SHA-256 72666ee5feab1953…

MALICIOUS

PDF

16.1 KB Created: 2019-05-03 05:02:28 +01:00 Authoring application: mPDF 5.7
MD5: f7426fbc5751ebefe67ba7941662f835 SHA-1: 47b26ba457c2bbe16759bcba05821ba924a8e455 SHA-256: 72666ee5feab1953678682d024592b28943d11bd124dbfd0598a86ada1910274
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, which is a common technique for distributing malicious content or phishing lures. While the specific URLs extracted were labeled as benign, the heuristic firing indicates a malicious intent to direct users to external resources. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample, but the embedded links suggest a phishing or content-luring attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6096099097090098/No-Witness-But-the-Moon-Jimmy-Vega-Mystery-3-by-Suzanne-Chazin.pdf
    • http://loaminoo.linkpc.net/3094099093096099/A-Blossom-of-Bright-Light-Jimmy-Vega-Mystery-2-by-Suzanne-Chazin.pdf
    • http://loaminoo.linkpc.net/3095091091099099/Land-of-Careful-Shadows-Jimmy-Vega-Mystery-1-by-Suzanne-Chazin.pdf
    • http://loaminoo.linkpc.net/4096092097092094/The-Passionate-Eye-The-Collected-Writing-of-Suzanne-Vega-by-Suzanne-Vega.pdf
    • http://loaminoo.linkpc.net/4092091094095098/Fireplay-by-Suzanne-Chazin.pdf
    • http://loaminoo.linkpc.net/4091091097093090/Flashover-Georgia-Skeehan-2-by-Suzanne-Chazin.pdf
    • http://loaminoo.linkpc.net/8095094096099090/The-Only-Witness-Neema-Mystery-1-by-Pamela-Beason.pdf
    • http://loaminoo.linkpc.net/7096090091099098/Jimmy-Jones-Puzzles-The-Mystery-of-Blackhill-Estate-by-Bogumil-Kaczynski.pdf
    • http://loaminoo.linkpc.net/2098090091095099/Evil-Relations-formerly-published-as-Witness-The-Man-Who-Bore-Witness-Against-the-Moors-Murderers-by-David-Smith.pdf
    • http://loaminoo.linkpc.net/9098093091097098/Moon-Lake-Hate-Ghost-Trouble-Witch-Rescue-Moon-Lake-Mystery-6-by-Lucia-Kuhl.pdf
    • http://loaminoo.linkpc.net/4092095091099095/Silent-Witness-Witness-Series-2-by-Rebecca-Forster.pdf
    • http://loaminoo.linkpc.net/1095093099093092/Hostile-Witness-Witness-Series-1-by-Rebecca-Forster.pdf
    • http://loaminoo.linkpc.net/4098098095098099/A-Hostage-To-Heritage-Michael-Stoddard-American-Revolution-Mystery-3-by-Suzanne-Adair.pdf
    • http://loaminoo.linkpc.net/3096094091092092/Mystery-of-the-Jaguar-Moon-A-Novel-Curriculum-1-by-Lisa-D-Lee.pdf
    • http://loaminoo.linkpc.net/1096092092096098/Captain-Raptor-and-the-Moon-Mystery-by-Kevin-O-39-Malley.pdf
    • http://loaminoo.linkpc.net/4098099090093094/Murder-Under-a-Mystic-Moon-A-Chintz-n-China-Mystery-3-by-Yasmine-Galenorn.pdf
    • http://loaminoo.linkpc.net/3095098098094095/Times-s-Witness-Times-s-Witness-by-Michael-Malone.pdf
    • http://loaminoo.linkpc.net/1092098091090097/Murder-In-Half-Moon-Bay-A-Jillian-Bradley-Mystery-1-by-Nancy-Jill-Thames.pdf
    • http://loaminoo.linkpc.net/4096093096090/Jimmy-Coates-Sabotage-Jimmy-Coates-4-by-Joe-Craig.pdf
    • http://loaminoo.linkpc.net/6094093099097/Jimmy-Coates-Blackout-Jimmy-Coates-7-by-Joe-Craig.pdf