Malicious PDF — malware analysis report

Static analysis result for SHA-256 79b1ad51dc86985a…

MALICIOUS

PDF

17.1 KB Created: 2019-05-02 19:08:24 +01:00 Authoring application: mPDF 5.7
MD5: cb6ea5734bc43e21e3c648f71f978fc6 SHA-1: f1b5834d4df3c4fa26a2d35feb3596e24ad7f8ed SHA-256: 79b1ad51dc86985af865f52758e88e88b64349946855a91bf8ff531ef93ac07e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm, directing users to external PDF files. This behavior is indicative of a phishing or spam campaign aiming to drive traffic to potentially malicious or unwanted content. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine a more specific attack pattern beyond link distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6095092096097092/Crisis-on-Kepler-Kepler-Chronicles-1-by-Lawrence-Del-Gigante.pdf
    • http://loaminoo.linkpc.net/6095092096097099/Selections-from-Kepler-s-Astronomia-Nova-by-Johannes-Kepler.pdf
    • http://loaminoo.linkpc.net/6095092096094095/Kepler-by-Max-Caspar.pdf
    • http://loaminoo.linkpc.net/4092099090099091/The-Nightmare-by-Lars-Kepler.pdf
    • http://loaminoo.linkpc.net/6095092097093098/Tempting-Kepler-by-J-S-Luxor.pdf
    • http://loaminoo.linkpc.net/6095092098091093/Love-YA-Like-a-Sister-by-Tom-Kepler.pdf
    • http://loaminoo.linkpc.net/4093091092091094/The-Fire-Witness-by-Lars-Kepler.pdf
    • http://loaminoo.linkpc.net/5090099090096090/Kepler-Revolutions-Trilogy-2-by-John-Banville.pdf
    • http://loaminoo.linkpc.net/6095092096098090/A-History-of-Astronomy-from-Thales-to-Kepler-by-J-L-E-Dreyer.pdf
    • http://loaminoo.linkpc.net/6095092098092091/Kepler-s-Philosophy-and-the-New-Astronomy-by-Rhonda-Martens.pdf
    • http://loaminoo.linkpc.net/6095092096097090/Johannes-Kepler-and-the-New-Astronomy-by-James-R-Voelkel.pdf
    • http://loaminoo.linkpc.net/6095092097097093/Kepler-and-the-Universe-How-One-Man-Revolutionized-Astronomy-by-David-Love.pdf
    • http://loaminoo.linkpc.net/6095092096094099/Epitome-of-Copernican-Astronomy-and-Harmonies-of-the-World-by-Johannes-Kepler.pdf
    • http://loaminoo.linkpc.net/6095092098091094/A-World-of-Great-Fiction-Free-Sampler-by-Lars-Kepler.pdf
    • http://loaminoo.linkpc.net/1091091096096098096/The-Musical-Order-of-the-World-Kepler-Hesse-Hindemith-by-Siglind-Bruhn.pdf
    • http://loaminoo.linkpc.net/6095092096098092/Confessions-of-an-American-Doctor-A-true-story-of-greed-ego-and-loss-of-ethics-by-Max-Kepler.pdf
    • http://loaminoo.linkpc.net/6095092098091099/A-Kepler-s-Dozen-Thirteen-Stories-about-Distant-Worlds-That-Really-Exist-by-Steve-B-Howell.pdf
    • http://loaminoo.linkpc.net/6095092097097096/Recentering-the-Universe-The-Radical-Theories-of-Copernicus-Kepler-Galileo-and-Newton-by-Ron-Miller.pdf
    • http://loaminoo.linkpc.net/8099094094093099/Der-Hypnotiseur-Paganinis-Fluch-Zwei-Joona-Linna-Romane-in-einem-Band-by-Lars-Kepler.pdf
    • http://loaminoo.linkpc.net/4094096091095092/Kepler-s-Witch-An-Astronomer-s-Discovery-of-Cosmic-Order-Amid-Religious-War-Political-Intrigue-and-the-Heresy-Trial-of-His-Mother-by-James-A-Connor.pdf