Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb9b27322e08a7a6…

MALICIOUS

PDF

16.8 KB Created: 2019-05-01 20:06:46 +01:00 Authoring application: mPDF 5.7
MD5: 1994395e16d87fe31d5d1fa115e0f212 SHA-1: 7ea9ac02e7d2c423e2b1eab0b67b2f3ebc52dbcc SHA-256: cb9b27322e08a7a6e06d1914c0054ea08a52d02d0f1daaeda035d4afc6e0791b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of the linked PDFs appear benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO spam or to distribute further malware. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5098093091092090/Tony-Robbins-His-Best-Insights-tony-robbins-anthony-robbins-unleash-the-power-within-unlimited-power-bandler-nlp-hypnosis-success-by-Jim-Bandler.pdf
    • http://loaminoo.linkpc.net/3096093090095099/Unleash-The-Power-Within-Personal-Coaching-From-Anthony-Robbins-That-Will-Transform-Your-Life-by-Anthony-Robbins.pdf
    • http://loaminoo.linkpc.net/6095092093092090/The-Essential-Elinor-Glyn-Collection-by-Elinor-Glyn.pdf
    • http://loaminoo.linkpc.net/4093096093090091/Wonder-Horse-The-True-Story-of-the-World-s-Smartest-Horse-by-Emily-Arnold-McCully.pdf
    • http://loaminoo.linkpc.net/1091091098096090/The-Horse-Charmer-Phantom-Stallion-Wild-Horse-Island-1-by-Terri-Farley.pdf
    • http://loaminoo.linkpc.net/4096096090098099/Cross-Train-Your-Horse-Book-One-Simple-Dressage-for-Every-Horse-Every-Sport-by-Jane-Savoie.pdf
    • http://loaminoo.linkpc.net/4099094097098092/Sun-Horse-Moon-Horse-by-Rosemary-Sutcliff.pdf
    • http://loaminoo.linkpc.net/2092097092090090/War-Horse-War-Horse-1-by-Michael-Morpurgo.pdf
    • http://loaminoo.linkpc.net/1099091092099090/The-Heavenly-Horse-from-the-Outermost-West-Heavenly-Horse-1-by-Mary-Stanton.pdf
    • http://loaminoo.linkpc.net/6091092094098093/Green-Horse-Winter-The-Green-Horse-Hotel-2-by-Isolde-Pullum.pdf
    • http://loaminoo.linkpc.net/6095092094095091/Halcyone-by-Elinor-Glyn.pdf
    • http://loaminoo.linkpc.net/6095092093092095/His-Hour-by-Elinor-Glyn.pdf
    • http://loaminoo.linkpc.net/3094096093097095/Far-from-Heaven-by-Glyn-Davis.pdf
    • http://loaminoo.linkpc.net/1091093091092098/Out-of-the-Rain-by-Glyn-Maxwell.pdf
    • http://loaminoo.linkpc.net/1090094095091094/Rest-for-the-Wicked-by-Glyn-Maxwell.pdf
    • http://loaminoo.linkpc.net/2094093094090098/The-Nerve-Poems-by-Glyn-Maxwell.pdf
    • http://loaminoo.linkpc.net/6095092093091099/The-Cambridge-Murders-by-Glyn-Daniel.pdf
    • http://loaminoo.linkpc.net/6095092092090099/The-Revolt-of-Owain-Glyn-Dwr-by-R-R-Davies.pdf
    • http://loaminoo.linkpc.net/9092097099096091/Tove-Jansson-by-W-Glyn-Jones.pdf
    • http://loaminoo.linkpc.net/1090098099099097095/Lewker-in-Tirol-by-Glyn-Carr.pdf
    • http://loaminoo.linkpc.net/4096096090098099/Cross-Train-Your-Horse-Book-One-Simple-Dressa