Malicious PDF — malware analysis report

Static analysis result for SHA-256 7767d4c0edef71fc…

MALICIOUS

PDF

14.0 KB Created: 2019-05-01 20:05:47 +01:00 Authoring application: mPDF 5.7
MD5: 1d6d35ad063199027b1c977e2a94e4e8 SHA-1: 77c8f7156feb000d76b1d4414b59e7ad0bd52edb SHA-256: 7767d4c0edef71fc3ad841df0b33ca8cdaad109507e269fc16d5b3612b11ea0f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on a dynamic DNS domain. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7096094095094/Crystal-by-Katie-Price.pdf
    • http://loaminoo.linkpc.net/3099093097094095/You-Only-Live-Once-by-Katie-Price.pdf
    • http://loaminoo.linkpc.net/4095096097098091/Stage-Fright-Perfect-Ponies-10-by-Katie-Price.pdf
    • http://loaminoo.linkpc.net/5099093094094099/Vincent-Price-A-Daughter-s-Biography-by-Victoria-Price.pdf
    • http://loaminoo.linkpc.net/9098094095/Chocolate-Covered-Katie-Over-80-Delicious-Recipes-That-Are-Secretly-Good-for-You-by-Katie-Higgins.pdf
    • http://loaminoo.linkpc.net/3097096092095098/Katie-s-Hellion-amp-Katie-s-Hope-Rhyn-Trilogy-1-2-by-Lizzy-Ford.pdf
    • http://loaminoo.linkpc.net/8093095090098098/The-Road-to-Price-Price-1-by-Justine-Elvira.pdf
    • http://loaminoo.linkpc.net/1094094098094092/The-Road-to-Price-Price-1-by-Justine-Elvira.pdf
    • http://loaminoo.linkpc.net/3091095093094099/Katie-and-the-Mustang-Book-1-Hoofbeats-Katie-and-the-Mustang-1-by-Kathleen-Duey.pdf
    • http://loaminoo.linkpc.net/1090099096092093097/Katie-and-the-Mustang-Hoofbeats-Katie-and-the-Mustang-4-by-Kathleen-Duey.pdf
    • http://loaminoo.linkpc.net/1090099096091098093/Katie-and-the-Mustang-2-Hoofbeats-Katie-and-the-Mustang-2-by-Kathleen-Duey.pdf
    • http://loaminoo.linkpc.net/4097097095098091/I-m-Still-Standing-by-Mel-Carnegie.pdf
    • http://loaminoo.linkpc.net/4097093095098099/Standing-Still-by-Kelly-Simmons.pdf
    • http://loaminoo.linkpc.net/3095099099097095/Last-Man-Standing-by-Keith-Taylor.pdf
    • http://loaminoo.linkpc.net/4099099090092097/Price-of-Privilege-Price-of-Privilege-3-by-Jessica-Dotta.pdf
    • http://loaminoo.linkpc.net/5092091098094095/Husk-Poems-by-Chris-Price-by-Chris-Price.pdf
    • http://loaminoo.linkpc.net/6092096091091097/Spirals-by-Ruby-Standing-Deer.pdf
    • http://loaminoo.linkpc.net/1094094090092093/Standing-in-the-Rainbow-by-Fannie-Flagg.pdf
    • http://loaminoo.linkpc.net/1097096094094097/Cordyceps-Last-Man-Standing-2-by-Keith-Taylor.pdf
    • http://loaminoo.linkpc.net/4093093092093098/Stones-by-Ruby-Standing-Deer.pdf