Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a65035292a70c2a…

MALICIOUS

PDF

16.2 KB Created: 2019-04-29 23:30:43 +01:00 Authoring application: mPDF 5.7
MD5: 3d1979e120cc303f10ed2dafdbf99563 SHA-1: b2721e7b3fe2a266c21e428000356165cbcd8f83 SHA-256: 7a65035292a70c2a603b8a9ab60ca11cf1f766856c561f78e703e1b823b96305
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier also flagged this PDF as malicious with high confidence. The URLs are hosted on a dynamic DNS domain, suggesting an attempt to obscure the true hosting location.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7091098095099092/Conference-Interpreting-Principles-and-Practice-by-Valerie-Taylor-Bouladon.pdf
    • http://loaminoo.linkpc.net/2091093098092097/Prism-Psyne-2-by-Jasmine-Angell.pdf
    • http://loaminoo.linkpc.net/2091093097090097/The-Black-Prism-Lightbringer-1-by-Brent-Weeks.pdf
    • http://loaminoo.linkpc.net/2098099093091093/The-Black-Prism-Lightbringer-1-by-Brent-Weeks.pdf
    • http://loaminoo.linkpc.net/3095098098099094/The-Black-Prism-Lightbringer-1-by-Brent-Weeks.pdf
    • http://loaminoo.linkpc.net/2091099096097091/Prism-The-Color-Alchemist-1-by-Nina-Walker.pdf
    • http://loaminoo.linkpc.net/2091092098098096/The-Black-Prism-Lightbringer-1-by-Brent-Weeks.pdf
    • http://loaminoo.linkpc.net/2097096090097093/The-Black-Prism-Lightbringer-1-by-Brent-Weeks.pdf
    • http://loaminoo.linkpc.net/1090097097093/The-Black-Prism-Lightbringer-1-by-Brent-Weeks.pdf
    • http://loaminoo.linkpc.net/3090099098097090/Dreams-of-Darkness-Rising-Prism-1-by-Ross-M-Kitson.pdf
    • http://loaminoo.linkpc.net/3097093096099091/The-Daemon-Prism-Collegia-Magica-3-by-Carol-Berg.pdf
    • http://loaminoo.linkpc.net/9098095099098091/The-Obsidian-Oracle-Dark-Sun-Prism-Pentad-4-by-Troy-Denning.pdf
    • http://loaminoo.linkpc.net/5095096098092092/The-Verdant-Passage-Dark-Sun-Prism-Pentad-1-by-Troy-Denning.pdf
    • http://loaminoo.linkpc.net/6094097096099091/The-Valerie-Dearborn-Trilogy-Valerie-Dearborn-1-3-by-Caroline-Hanson.pdf
    • http://loaminoo.linkpc.net/1090092096091099/Hudson-Taylor-In-Early-Years--The-Growth-of-a-Soul-by-Howard-Taylor.pdf
    • http://loaminoo.linkpc.net/3096095096090094/Spiritual-Secret-of-Hudson-Taylor-by-Howard-Taylor.pdf
    • http://loaminoo.linkpc.net/2095095097091099/Lee-s-Adjutant-The-Wartime-Letters-of-Colonel-Walter-Herron-Taylor-1862-1865-by-Walter-H-Taylor.pdf
    • http://loaminoo.linkpc.net/7090099098094094/The-Whole-Works-of-the-Right-REV-Jeremy-Taylor-Worthy-Communicant-Supplement-of-Sermons-Collection-of-Offices-by-Jeremy-Taylor.pdf
    • http://loaminoo.linkpc.net/4099095092090094/Taylor-Davis-and-the-Flame-of-Findul-Taylor-Davis-1-by-Michelle-Isenhoff.pdf
    • http://loaminoo.linkpc.net/1098097091091093/Elizabeth-Taylor-My-Love-Affair-with-Jewelry-by-Elizabeth-Taylor.pdf