Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d59fb6028132c08…

MALICIOUS

PDF

15.7 KB Created: 2019-04-30 03:14:39 +01:00 Authoring application: mPDF 5.7
MD5: 0988e29384ea8e7ada021d3b5d2853c5 SHA-1: 4f807b7517fca569f71587a183bb4bfb60070354 SHA-256: 7d59fb6028132c08dbc462854c075684a0a7f97d0448d9118c47926a9a2b24df
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, hosted on a dynamic DNS domain. This behavior is indicative of SEO poisoning or a content distribution scheme. While the specific content of the linked PDFs is benign, the overall structure and the ML classifier's high confidence score suggest a malicious intent, possibly to distribute further malware or engage in phishing. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098097098098096/Stowaway-Travelers-2-by-Becky-Black.pdf
    • http://loaminoo.linkpc.net/4092097099095097/Stowaway-Travelers-2-by-Becky-Black.pdf
    • http://loaminoo.linkpc.net/2098097094097090/Liar-s-Waltz-Travelers-1-by-Becky-Black.pdf
    • http://loaminoo.linkpc.net/4092097099095099/Tempting-the-Stars-Red-Dragon-3-by-Becky-Black.pdf
    • http://loaminoo.linkpc.net/2095095097091/The-Lady-Travelers-Guide-to-Larceny-with-a-Dashing-Stranger-The-Lady-Travelers-Society-2-by-Victoria-Alexander.pdf
    • http://loaminoo.linkpc.net/2090094092094090/The-Lady-Travelers-Guide-to-Scoundrels-amp-Other-Gentlemen-The-Lady-Travelers-Society-1-by-Victoria-Alexander.pdf
    • http://loaminoo.linkpc.net/1094096091099097/The-Pirate-s-Stowaway-Bride-by-Anne-Stryker.pdf
    • http://loaminoo.linkpc.net/1097095095094098/The-Travelers-by-K-L-Kranes.pdf
    • http://loaminoo.linkpc.net/7091090092093092/Travelers-Rest-by-Ann-Tatlock.pdf
    • http://loaminoo.linkpc.net/2094096096094097/The-Traveling-Man-The-Travelers-1-by-Michael-P-King.pdf
    • http://loaminoo.linkpc.net/3090092090096/Patalosh-The-Time-Travelers-by-Z-Altug.pdf
    • http://loaminoo.linkpc.net/4093094096090/Parallel-Travelers-1-by-Claudia-Lefeve.pdf
    • http://loaminoo.linkpc.net/1093094098098096/The-Travelers-Pendragon-Before-the-War-1-by-Carla-Jablonski.pdf
    • http://loaminoo.linkpc.net/8099091096099097/Watercolor-Sketching-for-Travelers-by-Peter-McReynolds.pdf
    • http://loaminoo.linkpc.net/1091090091093096097/The-International-Travelers-Guide-to-Bartering-by-Ian-Fasnacht.pdf
    • http://loaminoo.linkpc.net/7096099097090092/Travelers-Tales-Brazil-by-Annette-Haddad.pdf
    • http://loaminoo.linkpc.net/2098090098098/The-Strange-Hours-Travelers-Keep-Poems-by-August-Kleinzahler.pdf
    • http://loaminoo.linkpc.net/4091098091095098/The-Travelers-Club-and-the-Ghost-Ship-by-Michael-Bradley.pdf
    • http://loaminoo.linkpc.net/4096098094093097/Chromeheart-Travelers-Series-Book-II-by-Alia-Hess.pdf
    • http://loaminoo.linkpc.net/4093098091095092/Travel-Guide-for-Budget-Travelers-by-Raul-Fattore.pdf