Malicious PDF — malware analysis report

Static analysis result for SHA-256 7986c6a7527677dc…

MALICIOUS

PDF

14.2 KB Created: 2019-05-07 08:29:27 +01:00 Authoring application: mPDF 5.7
MD5: 5b2dbbf58da42b72a2989fd860c0c33f SHA-1: c3995f7274913a3f16603f10599b82f09760f3f6 SHA-256: 7986c6a7527677dc0a417f55e1c35adfe537d2dcf385b1a464f12acd11714704
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links to external PDF files, hosted on a dynamic DNS domain. This behavior is indicative of a link farm or a phishing lure, aiming to direct users to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3097098095093091/Bear-With-Me-Northern-Bears-1-by-Jade-Buchanan.pdf
    • http://loaminoo.linkpc.net/5090097093090093/Firestorm-by-Jade-Buchanan.pdf
    • http://loaminoo.linkpc.net/1094090093097092/Bears-Dancing-in-the-Northern-Air-by-Christiane-Jacox-Kyle.pdf
    • http://loaminoo.linkpc.net/9097093096092093/Blackjack-Bears-Gavin-Koche-Brothers-3-by-Amelia-Jade.pdf
    • http://loaminoo.linkpc.net/2099099095096098/A-Beta-for-Two-Bears-Bear-Mountain-9-by-Kelex.pdf
    • http://loaminoo.linkpc.net/2099099095094096/Redemption-for-Two-Bears-Bear-Mountain-7-by-Kelex.pdf
    • http://loaminoo.linkpc.net/1099099099093090/Crying-Bear-Yes-Bears-Cry-Sometimes-Too-by-Virginia-Wright.pdf
    • http://loaminoo.linkpc.net/2099099099091098/Finding-His-Two-Bears-Bear-Mountain-11-by-Kelex.pdf
    • http://loaminoo.linkpc.net/2099099095094094/Surrendering-to-Two-Bears-Bear-Mountain-8-by-Kelex.pdf
    • http://loaminoo.linkpc.net/3090098098090094/Bear-the-Burn-Fire-Bears-2-by-T-S-Joyce.pdf
    • http://loaminoo.linkpc.net/3090098098095094/Bear-the-Heat-Fire-Bears-3-by-T-S-Joyce.pdf
    • http://loaminoo.linkpc.net/4090094097093094/The-Bear-s-Fake-Bride-Bears-With-Money-1-by-Amy-Star.pdf
    • http://loaminoo.linkpc.net/6092092095091093/Bear-Set-Match-The-McClintock-Bears-2-by-Charlotte-Summers.pdf
    • http://loaminoo.linkpc.net/1098094096092091/A-Fox-Between-the-Bear-s-Sheets-Wylde-Bears-2-by-Jenika-Snow.pdf
    • http://loaminoo.linkpc.net/7091096090097099/Geek-Bear-Rescue-Bears-6-by-Scarlett-Grove.pdf
    • http://loaminoo.linkpc.net/4091093099096095/Baby-It-s-Cold-Out-Bear-Fire-Bears-4-by-T-S-Joyce.pdf
    • http://loaminoo.linkpc.net/1098094096091099/Bared-for-Her-Bear-Wylde-Bears-1-by-Jenika-Snow.pdf
    • http://loaminoo.linkpc.net/9095095099093099/The-Bear-s-Wedding-Date-Alaskan-Bears-2-by-Tiffany-Allee.pdf
    • http://loaminoo.linkpc.net/9095095099094091/The-Bear-s-Unexpected-Fate-Alaskan-Bears-3-by-Tiffany-Allee.pdf
    • http://loaminoo.linkpc.net/4090094097093093/Big-Bear-Daddy-Sweetwater-Father-Bears-1-by-Anya-Nowlan.pdf