Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e9a716c2929564c…

MALICIOUS

PDF

17.4 KB Created: 2019-05-02 05:10:44 +01:00 Authoring application: mPDF 5.7
MD5: 20827374b3b2e7b5dd09a4d033e76b38 SHA-1: 228dc5bb64f8e3506ec0c25bb35baa7636012efc SHA-256: 7e9a716c2929564cbd3a13554bdb4b93d0b013af2969fb2b3d2e7be23d1ff2d6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links were classified as confirmed_benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to act as a landing page for further attacks. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3092093095099096/Bar-a-The-Making-of-the-Greatest-Team-in-the-World-by-Graham-Hunter.pdf
    • http://loaminoo.linkpc.net/1091098098097096090/Am-I-Making-Myself-Clear-Secrets-of-the-World-s-Greatest-Communicators-by-Terry-Felber.pdf
    • http://loaminoo.linkpc.net/7099093091098/Dragon-Ball-Z-Vol-1-The-World-s-Greatest-Team-Dragon-Ball-Z-1-by-Akira-Toriyama.pdf
    • http://loaminoo.linkpc.net/3090090096095096/Turned-Gay-by-the-Basketball-Team-by-Hunter-Fox.pdf
    • http://loaminoo.linkpc.net/2095090096098092/Harriers-The-Making-of-a-Championship-Cross-Country-Team-by-Joseph-Shivers.pdf
    • http://loaminoo.linkpc.net/1099098091096094/Ryan-Hunter-Grover-Beach-Team-2-by-Piper-Shelly.pdf
    • http://loaminoo.linkpc.net/5090094098098/The-Nazi-Hunters-How-a-Team-of-Spies-and-Survivors-Captured-the-World-s-Most-Notorious-Nazis-How-a-Team-of-Spies-and-Survivors-Captured-the-World-s-Most-Notorious-Nazi-by-Neal-Bascomb.pdf
    • http://loaminoo.linkpc.net/3093090093093091/Unstuck-A-Tool-for-Yourself-Your-Team-and-Your-World-by-Keith-Yamashita.pdf
    • http://loaminoo.linkpc.net/2095096097094094/Team-Rodent-How-Disney-Devours-the-World-by-Carl-Hiaasen.pdf
    • http://loaminoo.linkpc.net/6097094099092099/The-World-s-Greatest-Mysteries-by-Nigel-Blundell.pdf
    • http://loaminoo.linkpc.net/5092090096097095/The-World-s-Greatest-Lion-by-Ralph-Helfer.pdf
    • http://loaminoo.linkpc.net/1090093092095092092/FCBD-World-s-Greatest-Cartoonists-by-Jason.pdf
    • http://loaminoo.linkpc.net/6097094098094090/The-World-s-Greatest-Ghosts-by-Nigel-Blundell.pdf
    • http://loaminoo.linkpc.net/5096092095091095/The-Pizza-Book-Everything-There-Is-To-Know-About-the-World-s-Greatest-Pie-by-Evelyne-Slomon.pdf
    • http://loaminoo.linkpc.net/3098092097094094/The-World-s-Greatest-Adventure-Machine-by-Frank-L-Cole.pdf
    • http://loaminoo.linkpc.net/1091096091099097098/Darjeeling-A-History-of-the-World-s-Greatest-Tea-by-Jeff-Koehler.pdf
    • http://loaminoo.linkpc.net/9090095091097/Quantum-and-Woody-Volume-1-The-World-s-Worst-Superhero-Team-by-James-Asmus.pdf
    • http://loaminoo.linkpc.net/4093097095092090/Red-Nile-A-Biography-of-the-World-s-Greatest-River-by-Robert-Twigger.pdf
    • http://loaminoo.linkpc.net/6097094099094091/The-World-s-Greatest-Scandals-of-the-20th-Century-by-Nigel-Blundell.pdf
    • http://loaminoo.linkpc.net/8092093097097094/The-World-s-Greatest-Traveller-Ibn-Battouta-by-Denys-Johnson-Davies.pdf
    • http://loaminoo.linkpc.net/5090094098098/The-Nazi-Hunters-How-a-Team-of-Spies-and-Survivors-Captured-the-World-s-Most-Notorious-Nazis-How-a-Team-of-Spies-and-Survivors-Captured-the-World-s-Most-Notorious