Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c23c0bfd1b7296d…

MALICIOUS

PDF

18.7 KB Created: 2019-05-02 05:21:31 +01:00 Authoring application: mPDF 5.7
MD5: fbc94b0d1f464923ee49de65d14f00d1 SHA-1: d3f388d963058387223e16be5c56fc28ba833de9 SHA-256: 7c23c0bfd1b7296da2ff78df24d18b26256dae30fda49c501f12a14387c6103d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which are likely intended to redirect users to malicious sites. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document as malicious. While no scripts were extracted, the embedded URLs themselves serve as the primary indicators of compromise and suggest a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3093093098091090/Stories-The-Collected-Short-Fiction-by-Helen-Garner.pdf
    • http://loaminoo.linkpc.net/3092096099094092/Infinite-Waters-9-1-Speculative-Fiction-Short-Stories-Short-SSF-Stories-Book-2-by-Nicholas-C-Rossis.pdf
    • http://loaminoo.linkpc.net/3093091093092098/Mindscapes-Ten-Science-Fiction-and-Speculative-Fiction-Short-Stories-by-Victor-D-Lopez.pdf
    • http://loaminoo.linkpc.net/2099090096091096/Mindscapes-Ten-Science-Fiction-and-Speculative-Fiction-Short-Stories-by-Victor-D-Lopez.pdf
    • http://loaminoo.linkpc.net/5096098095091091/The-Collected-Fantasies-Vol-4-The-Long-Tomorrow-and-Other-Science-Fiction-Stories-The-Collected-Fantasies-of-Jean-Giraud-4-by-M-bius.pdf
    • http://loaminoo.linkpc.net/5098095095092/Gateways-to-Abomination-Collected-Short-Fiction-by-Matthew-M-Bartlett.pdf
    • http://loaminoo.linkpc.net/2096093093099/Novelties-and-Souvenirs-Collected-Short-Fiction-by-John-Crowley.pdf
    • http://loaminoo.linkpc.net/1093098095099090/Collected-Short-Stories-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/4094094095099099/Collected-Short-Stories-Volume-4-by-W-Somerset-Maugham.pdf
    • http://loaminoo.linkpc.net/3092096099093091/In-the-Shadows-of-the-Onion-Domes-Collected-Short-Stories-by-Mary-Pat-Hyland.pdf
    • http://loaminoo.linkpc.net/4094094097092092/Flash-Fiction-72-Very-Short-Stories-by-James-Thomas.pdf
    • http://loaminoo.linkpc.net/4094095099091095/12-Science-Fiction-Short-Stories-by-Philip-K-Dick.pdf
    • http://loaminoo.linkpc.net/1091099090096094091/Village-Stories-A-Collection-of-Short-Fiction-by-Lucette-Desvignes.pdf
    • http://loaminoo.linkpc.net/8091094093098096/Flash-Fiction-International-Very-Short-Stories-from-Around-the-World-by-James-Thomas.pdf
    • http://loaminoo.linkpc.net/2093094096091093/Confessions-Fact-or-Fiction-A-Collection-of-Short-Stories-and-Memoir-by-Herta-B-Feely.pdf
    • http://loaminoo.linkpc.net/1091093090098098094/Ramblings-of-a-reckless-man-By-Mario-L-Hicks-Flash-fiction-and-short-stories-Book-1-by-Pedro-Jaun.pdf
    • http://loaminoo.linkpc.net/1091098096094096095/The-Scribner-Anthology-of-Contemporary-Short-Fiction-Fifty-North-American-Stories-Since-1970-by-Lex-Williford.pdf
    • http://loaminoo.linkpc.net/4093090092095095/Collected-Folk-Tales-by-Alan-Garner.pdf
    • http://loaminoo.linkpc.net/1090092094095094/Postcards-from-Surfers-by-Helen-Garner.pdf
    • http://loaminoo.linkpc.net/2097099092097092/This-House-of-Grief-by-Helen-Garner.pdf