Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d46ea2ac2a3faa4…

MALICIOUS

PDF

20.6 KB Created: 2019-05-01 23:37:46 +01:00 Authoring application: mPDF 5.7
MD5: 26f0607ab44314d6f16c337fe1c8d30c SHA-1: 14f222164b4fa7e7eb172ceb4f0d61fbf7be6129 SHA-256: 9d46ea2ac2a3faa437624b301d6354540ee39bad30a71ccfa985449ea2dff39f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While many of these links were classified as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS firing suggest a malicious intent, likely to drive traffic or distribute malware. No scripts were extracted from this sample, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7094090093096096/Dawkins-God-Genes-Memes-and-the-Meaning-of-Life-by-Alister-E-McGrath.pdf
    • http://loaminoo.linkpc.net/2093094097095093/The-Passionate-Intellect-Christian-Faith-and-the-Discipleship-of-the-Mind-by-Alister-E-McGrath.pdf
    • http://loaminoo.linkpc.net/7094090095099092/Memes-Ultimate-Memes-The-Funniest-LARGEST-Collection-of-Memes-on-the-Internet-by-Memes.pdf
    • http://loaminoo.linkpc.net/4095090095099099/Christianity-s-Dangerous-Idea-The-Protestant-Revolution-A-History-from-the-Sixteenth-Century-to-the-Twenty-First-by-Alister-E-McGrath.pdf
    • http://loaminoo.linkpc.net/7094090094095093/The-Book-of-Supreme-Memes-Contains-Over-100-Hilarious-ROBLOX-Memes-and-Jokes-ROBLOX-Memes-Memes-for-kids-roblox-books-by-Anthony-Wright.pdf
    • http://loaminoo.linkpc.net/1091097097098093092/Luther-s-Theology-of-the-Cross-Martin-Luther-s-Theological-Breakthrough-by-Alister-E-McGrath.pdf
    • http://loaminoo.linkpc.net/7094090094094093/Memes-Memes-Memes-101-Fairy-Tail-Memes-by-Memes.pdf
    • http://loaminoo.linkpc.net/7094090095099093/Memes-Memes-Memes-Best-of-Sword-Art-Online-Memes-by-Memes.pdf
    • http://loaminoo.linkpc.net/1090099093097095/The-Path-to-Meaning-How-to-Align-Yourself-with-the-Universe-Make-Use-of-its-Hidden-Laws-and-Fill-Your-Life-with-Meaning-by-Agnes-Bodi.pdf
    • http://loaminoo.linkpc.net/7094090094098097/Men-s-Humor-Hilarious-Memes-Jokes-Quotes-amp-Pictures-For-Men-by-Memes.pdf
    • http://loaminoo.linkpc.net/7094090094094091/Memes-Best-Memes-2016-FREE-BONUS-by-Jeff-Harris.pdf
    • http://loaminoo.linkpc.net/7094090093097091/Memes-Memes-Memes-RWBY-Memes-by-Memes.pdf
    • http://loaminoo.linkpc.net/1091092092090090093/Best-Collection-of-dank-memes-Best-dank-memes-by-memes-professionals.pdf
    • http://loaminoo.linkpc.net/7094090095099094/Star-Wars-Funny-Memes-by-Memes.pdf
    • http://loaminoo.linkpc.net/7094090096090096/MINECRAFT-Memes-Funny-Memes-amp-NSFW-Minecraft-Meme-Book-2-by-Jackson-Lopez.pdf
    • http://loaminoo.linkpc.net/7094090093097090/Pokemon-Memes-Funny-Memes-amp-NSFW-Pokemon-book-1-by-Jackson-Lopez.pdf
    • http://loaminoo.linkpc.net/7094090093097093/Five-Nights-at-Freddy-s-Ultimate-Jokes-amp-Memes-Over-100-Funny-Five-Nights-at-Freddy-s-Memes-FNAF-Jokes-FNAF-Memes-fnaf-fnaf-2-fnaf-3-by-Memes.pdf
    • http://loaminoo.linkpc.net/1090093091097099090/Relative-Strangers-Family-Life-Genes-and-Donor-Conception-by-Petra-Nordqvist.pdf
    • http://loaminoo.linkpc.net/4094091092090093/My-Life-with-Deth-Discovering-Meaning-in-a-Life-of-Rock-Roll-by-David-Ellefson.pdf
    • http://loaminoo.linkpc.net/3096098090094/Jeremy-Fink-and-the-Meaning-of-Life-by-Wendy-Mass.pdf
    • http://loaminoo.linkpc.net/4095090095099099/Christianity-s-Dangerous-Idea-The-Protestant-Revolution-A-History-from-the-Sixteenth-Century-to-the-Twenty-First-by-Aliste