Malicious PDF — malware analysis report

Static analysis result for SHA-256 817937137c639116…

MALICIOUS

PDF

14.6 KB Created: 2019-04-30 05:37:57 +01:00 Authoring application: mPDF 5.7
MD5: 68fec20f0358fec585874acd4176645b SHA-1: a578611cf80ea935c56bbff71d60f281a3ad89cd SHA-256: 817937137c639116190b98a2b945b863d0d85798a1d036209c19d08598a80ee7
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs pointing to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of these links suggests an attempt to manipulate search engine results or distribute further content. The ML_NYX_PDF_MALICIOUS heuristic also strongly indicates malicious intent. No scripts were extracted, but the overall pattern suggests a malicious document delivery mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090091091099093093/A-Miracle-for-Mayfield-by-Gregory-F-Wasylak.pdf
    • http://loaminoo.linkpc.net/1090090090099099092/When-we-meet-a-person-of-destiny-a-miracle-happens-in-my-life-A-trajectory-to-a-miracle-meeting-Twin-Soul-by-Manami-Himekawa.pdf
    • http://loaminoo.linkpc.net/7096095097092096/Stardust-Miracle-Miracle-Interrupted-2-by-Edie-Ramer.pdf
    • http://loaminoo.linkpc.net/5095097093097094/Christmas-Miracle-in-July-Christmas-Miracle-Series-Book-1-by-R-M-Gauthier.pdf
    • http://loaminoo.linkpc.net/3098096090096097/The-Miracle-Girls-Miracle-Girls-1-by-Anne-Dayton.pdf
    • http://loaminoo.linkpc.net/1090091092090091098/Best-of-Curtis-Mayfield-by-Curtis-Mayfield.pdf
    • http://loaminoo.linkpc.net/1093091098093093/Drowning-Anna-by-Sue-Mayfield.pdf
    • http://loaminoo.linkpc.net/1090091091099092095/Poisoned-Voices-2-by-Sue-Mayfield.pdf
    • http://loaminoo.linkpc.net/1090091092090092091/Loving-Strangers-by-MAYFIELD.pdf
    • http://loaminoo.linkpc.net/8097098091095/On-Eagles-Wings-by-Sue-Mayfield.pdf
    • http://loaminoo.linkpc.net/1090091091099092096/The-Inheritance-Part-4-by-Olivia-Mayfield.pdf
    • http://loaminoo.linkpc.net/1090091092090091093/Mayfield-Bunny-by-Herbert-Feldman.pdf
    • http://loaminoo.linkpc.net/1090091091097091093/Curtis-Mayfield-by-Peter-Burns.pdf
    • http://loaminoo.linkpc.net/1090091091099092097/The-Inheritance-Part-5-by-Olivia-Mayfield.pdf
    • http://loaminoo.linkpc.net/1090091092090090095/Jeremy-Mayfield-by-Mike-Bonner.pdf
    • http://loaminoo.linkpc.net/1090091091098096093/The-Inheritance-Part-3-by-Olivia-Mayfield.pdf
    • http://loaminoo.linkpc.net/1090091091099092091/The-Inheritance-Part-2-by-Olivia-Mayfield.pdf
    • http://loaminoo.linkpc.net/1090091092090090094/The-Mayfield-Valley-by-Muriel-Hall.pdf
    • http://loaminoo.linkpc.net/1090091091099093094/The-Rollertcoaster-of-Mayfield-by-Morris-Striplin.pdf
    • http://loaminoo.linkpc.net/1097096097090097/Choices-Waiting-for-Forever-1-by-Jamie-Mayfield.pdf