Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5d375f84a0ca38b…

MALICIOUS

PDF

16.3 KB Created: 2019-05-02 17:41:25 +01:00 Authoring application: mPDF 5.7
MD5: bfc125ed21f287188e5ff71bfc18d5a7 SHA-1: f8619acc6310d7490d93574f59f9f96696c973ff SHA-256: b5d375f84a0ca38bf3d46c9d5bae6dc84226ccc0b8f5f1ded9743e40cfbbe769
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves directing users to a domain hosting numerous PDF files, likely as a lure or to distribute further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096096091095092/Area-1-Area-1-1-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/2093093095092093/Area-1-Area-1-2-by-Stella-Purple.pdf
    • http://loaminoo.linkpc.net/4094091095096094/The-Knight-in-the-Area-Vol-3-The-Knight-in-the-Area-3-by-Hiroaki-Igano.pdf
    • http://loaminoo.linkpc.net/1093099099090094/An-Area-of-Darkness-by-V-S-Naipaul.pdf
    • http://loaminoo.linkpc.net/4099094096091091/Area-7-by-Matthew-Reilly.pdf
    • http://loaminoo.linkpc.net/1094092093091092/The-Truth-Area-51-7-by-Robert-Doherty.pdf
    • http://loaminoo.linkpc.net/5090096090093097/Grey-Area-From-the-City-to-the-Sea-by-Tim-Bird.pdf
    • http://loaminoo.linkpc.net/3099093095099091/Ashes-The-Gray-Area-1-by-Stefanie-Ellis.pdf
    • http://loaminoo.linkpc.net/3090090099092098/Impacted-Bay-Area-Professionals-1-by-Mickie-B-Ashling.pdf
    • http://loaminoo.linkpc.net/4090092091094096/Bonds-of-Love-Bay-Area-Professionals-2-by-Mickie-B-Ashling.pdf
    • http://loaminoo.linkpc.net/3091091097095094/Area-50-Juan-A-Misplaced-Adventure-by-Karen-Jones.pdf
    • http://loaminoo.linkpc.net/5093097097092096/Heritage-of-the-Creve-Coeur-Area-by-Gloria-Dalton.pdf
    • http://loaminoo.linkpc.net/8090098096097096/Archivi-Territori-Poteri-in-Area-Estense-by-Euride-Fregni.pdf
    • http://loaminoo.linkpc.net/8094095098096091/The-Bay-Area-School-Californian-Artists-from-the-1950s-and-1960s-by-Anya-Perse.pdf
    • http://loaminoo.linkpc.net/2097099096091097/Case-Files-of-the-East-Area-Rapist-Golden-State-Killer-by-Kat-Winters.pdf
    • http://loaminoo.linkpc.net/1091093095097098094/Holy-Cross-Wilderness-Area-Northern-Trails-of-Eagle-County-by-Kim-Fenske.pdf
    • http://loaminoo.linkpc.net/3095090090092/Practicing-Angels-A-Contemporary-Anthology-of-San-Francisco-Bay-Area-Poetry-by-Michael-Mayo.pdf
    • http://loaminoo.linkpc.net/5098098090094098/Improving-Adolescent-Literacy-Content-Area-Strategies-at-Work-by-Douglas-Fisher.pdf
    • http://loaminoo.linkpc.net/6090093090099092/Relationship-Breakthrough-How-to-Create-Outstanding-Relationships-in-Every-Area-of-Your-Life-by-Cloe-Madanes.pdf
    • http://loaminoo.linkpc.net/5091091098090096/The-Electric-City-Energy-and-the-Growth-of-the-Chicago-Area-1880-1930-by-Harold-L-Platt.pdf