Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9d13cdd5669e8b7…

MALICIOUS

PDF

21.9 KB Created: 2019-04-30 03:35:59 +01:00 Authoring application: mPDF 5.7
MD5: 2c235254d7c029b84ac3be46a7d49319 SHA-1: b776447abac23bfa66f1ceb16ead73d541b3c0b4 SHA-256: a9d13cdd5669e8b7945d1be817d10263722bb7e0389a918d974d0960a333a79a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, identified by the PDF_SEO_LINK_FARM heuristic. While the ML classifier also flagged this as malicious, the primary attack pattern observed is the creation of a link farm designed to direct users to a large collection of documents. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7096095094095092/Secrets-of-the-Tomb-Skull-and-Bones-the-Ivy-League-and-the-Hidden-Paths-of-Power-by-Alexandra-Robbins.pdf
    • http://loaminoo.linkpc.net/5098093091092090/Tony-Robbins-His-Best-Insights-tony-robbins-anthony-robbins-unleash-the-power-within-unlimited-power-bandler-nlp-hypnosis-success-by-Jim-Bandler.pdf
    • http://loaminoo.linkpc.net/1094091092094098/Secrets-of-the-Lost-Mode-of-Prayer-The-Hidden-Power-of-Beauty-Blessings-Wisdom-and-Hurt-by-Gregg-Braden.pdf
    • http://loaminoo.linkpc.net/3096093090095099/Unleash-The-Power-Within-Personal-Coaching-From-Anthony-Robbins-That-Will-Transform-Your-Life-by-Anthony-Robbins.pdf
    • http://loaminoo.linkpc.net/2092093090095094/Pledged-The-Secret-Life-of-Sororities-by-Alexandra-Robbins.pdf
    • http://loaminoo.linkpc.net/8094094096099091/Quarterlife-Crisis-The-Unique-Challenges-of-Life-in-Your-Twenties-by-Alexandra-Robbins.pdf
    • http://loaminoo.linkpc.net/9097090098099098/Cults-Conspiracies-and-Secret-Societies-The-Straight-Scoop-on-Freemasons-The-Illuminati-Skull-and-Bones-Black-Helicopters-The-New-World-Order-and-many-many-more-by-Arthur-Goldwag.pdf
    • http://loaminoo.linkpc.net/3098092090095094/The-Emperor-of-Mars-Secrets-of-the-Dragon-Tomb-2-by-Patrick-Samphire.pdf
    • http://loaminoo.linkpc.net/8094094095090/Witch-s-Eight-Paths-of-Power-A-Complete-Course-in-Magick-and-Witchcraft-by-Sable-Aradia.pdf
    • http://loaminoo.linkpc.net/5099096091090/Secrets-of-Power-Negotiating-Inside-Secrets-from-a-Master-Negotiator-by-Roger-Dawson.pdf
    • http://loaminoo.linkpc.net/4090099097093097/The-Power-of-Nothingness-by-Alexandra-David-N-el.pdf
    • http://loaminoo.linkpc.net/2092091090094090/Blood-Secrets-Alexandra-Sabian-2-by-Jeannie-Holmes.pdf
    • http://loaminoo.linkpc.net/1091091094099094097/Ed-Marsmallow-Auch-Held-sein-will-gelernt-sein-Secrets-of-the-Dragon-Tomb-1-by-Patrick-Samphire.pdf
    • http://loaminoo.linkpc.net/7097099095096095/Pro-Hair-Care-Salon-Secrets-Of-The-Professionals-by-Alexandra-Friend.pdf
    • http://loaminoo.linkpc.net/3099090098092092/Hidden-Secrets-by-Cait-London.pdf
    • http://loaminoo.linkpc.net/3095092099097093/Seventh-Mark---Part-1-Hidden-Secrets-1-1-by-W-J-May.pdf
    • http://loaminoo.linkpc.net/3098096097091097/Kidding-Ourselves-The-Hidden-Power-of-Self-Deception-by-Joseph-T-Hallinan.pdf
    • http://loaminoo.linkpc.net/3090098097094093/The-Hidden-Stairs-and-the-Magic-Carpet-The-Secrets-of-Droon-1-by-Tony-Abbott.pdf
    • http://loaminoo.linkpc.net/2092099096096097/The-Book-of-Secrets-Unlocking-the-Hidden-Dimensions-of-Your-Life-by-Deepak-Chopra.pdf
    • http://loaminoo.linkpc.net/4093096097092098/Coming-Back-Stronger-Unleashing-the-Hidden-Power-of-Adversity-by-Drew-Brees.pdf
    • http://loaminoo.linkpc.net/3096093090095099/U