Malicious PDF — malware analysis report

Static analysis result for SHA-256 b560fd62ebf669d2…

MALICIOUS

PDF

25.3 KB Created: 2019-05-02 17:35:03 +01:00 Authoring application: mPDF 5.7
MD5: abf3048d0f5286ed169c57e85422f9b7 SHA-1: c192451a78f468a116ed925bac1932c17bacf140 SHA-256: b560fd62ebf669d2a02473d2b03223a840741a99816d1585b953df67105805f3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a critical heuristic for containing a mass external link farm, with 29 links detected. The embedded URLs, such as http://loaminoo.linkpc.net/4099092091099096/Muck-City-Winning-and-Losing-in-Football-s-Forgotten-Town-by-Bryan-Mealer.pdf, are likely part of a phishing or malware distribution scheme. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099092091099096/Muck-City-Winning-and-Losing-in-Football-s-Forgotten-Town-by-Bryan-Mealer.pdf
    • http://loaminoo.linkpc.net/4093097093095095/All-Things-Must-Fight-to-Live-Stories-of-War-and-Deliverance-in-Congo-by-Bryan-Mealer.pdf
    • http://loaminoo.linkpc.net/7091098095093/Football-Betting-How-To-Increase-Your-Chances-Of-Winning-by-Francis-Okumu.pdf
    • http://loaminoo.linkpc.net/4090096096091098/Losing-the-Rat-Race-Winning-at-Life-by-Marc-D-Angel.pdf
    • http://loaminoo.linkpc.net/5095096097091/How-To-Win-Football-Bets-Easily-Every-Time-Top-Secrets-Tips-And-Best-Strategies-For-Winning-Big-by-B-Guru.pdf
    • http://loaminoo.linkpc.net/6091095096093095/The-Undefeated-The-Oklahoma-Sooners-and-the-Greatest-Winning-Streak-in-College-Football-by-Jim-Dent.pdf
    • http://loaminoo.linkpc.net/7091097097097096/The-Holy-War-Made-by-Shaddai-Upon-Diabolus-for-the-Regaining-of-the-Metropolis-of-the-World-Or-the-Losing-and-Taking-Again-of-the-Town-of-Mansoul-1869-by-John-Bunyan.pdf
    • http://loaminoo.linkpc.net/2095090096092091/History-of-a-Disappearance-The-Story-of-a-Forgotten-Polish-Town-by-Filip-Springer.pdf
    • http://loaminoo.linkpc.net/1094092092097099/Football-Hero-Football-Genius-2-by-Tim-Green.pdf
    • http://loaminoo.linkpc.net/9094093091094098/Football-Outsiders-Almanac-2015-The-Essential-Guide-to-the-2015-NFL-and-College-Football-Seasons-by-Aaron-Schatz.pdf
    • http://loaminoo.linkpc.net/3097096090091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/4098093094096091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/1091094096093098094/Town-and-Revolution-Soviet-Architecture-and-City-Planning-1917-1935-by-Anatole-Kopp.pdf
    • http://loaminoo.linkpc.net/1092097098095094/Winning-Ace-The-Winning-Ace-1-by-Tracie-Delaney.pdf
    • http://loaminoo.linkpc.net/6095096093094099/Annual-Report-of-the-Town-Officers-of-the-Town-of-Barnstead-Comprising-Those-of-the-Selectmen-Treasurer-Collector-Road-Agents-School-Board-Town-Clerk-Trustees-of-the-Public-Library-Trustees-of-Trust-Funds-and-Fire-Warden-For-the-Year-Ending-Janua-by-Barnstead-New-Hampshire.pdf
    • http://loaminoo.linkpc.net/2096093096096095/Football-Sweetheart-Football-Sweetheart-1-by-Tiffany-A-White.pdf
    • http://loaminoo.linkpc.net/2092092092093098/The-Last-of-the-Doughboys-The-Forgotten-Generation-and-Their-Forgotten-World-War-by-Richard-Rubin.pdf
    • http://loaminoo.linkpc.net/2099098091092096/Better-Left-Forgotten-Forgotten-1-by-Lisa-Helen-Gray.pdf
    • http://loaminoo.linkpc.net/1090097095097095096/Muck-by-Robert-E-Jordan.pdf
    • http://loaminoo.linkpc.net/1090097095097092091/Medieval-Muck-by-Mary-Dobson.pdf
    • http://loaminoo.linkpc.net/7091097097097096/The-Holy-War