Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3d6e1ce61a25b6a…

MALICIOUS

PDF

18.3 KB Created: 2019-05-07 03:31:18 +01:00 Authoring application: mPDF 5.7
MD5: fc37af7fde95612e34c25512f38c4829 SHA-1: ea34a8b2c89688462693803a586cff8cc437870f SHA-256: d3d6e1ce61a25b6a853c051b170400c8c1d2875daef657c3146f5b9de7f8f75b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF was flagged by a machine learning classifier and contains a large number of embedded external links, characteristic of a link farm or a phishing lure. The primary heuristic indicates a 'PDF_SEO_LINK_FARM', suggesting the document's purpose is to direct users to a multitude of potentially malicious or deceptive websites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096092098099090/Western-genre-Novels-including-The-Dark-Tower-Ii-The-Drawing-Of-The-Three-The-Dark-Tower-The-Gunslinger-The-Dark-Tower-Iv-Wizard-And-Glass-The-Dark-Tower-Iii-The-Waste-Lands-The-Dark-Tower-V-Wolves-Of-The-Calla-The-Wind-Through-The-Keyhole-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/4092099095097094/The-Collected-Stories-of-Robert-Silverberg-Volume-1-Pluto-in-the-Morning-Light-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/4092099095096095/The-Collected-Stories-Of-Robert-Silverberg-Volume-Five-The-Palace-At-Midnight-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/4092099095096098/The-Collected-Stories-of-Robert-Silverberg-Volume-6-Multiples-1983-87-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/4099096097096091/The-Girl-in-the-Glass-Tower-by-Elizabeth-Fremantle.pdf
    • http://loaminoo.linkpc.net/3093094091097099/Tower-of-Dawn-Throne-of-Glass-6-by-Sarah-J-Maas.pdf
    • http://loaminoo.linkpc.net/1096094090092090/The-Man-in-the-Maze-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/1096093095090097/To-Open-The-Sky-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/2097093093096/Chains-of-the-Sea-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/2097094098099/To-Jorslem-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/3099098098098097/Nightwings-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/1090094097093097095/Es-stirbt-in-mir-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/2097090097092098/Nightwings-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/6099096092099093/To-Live-Again-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/1092093098094090/Those-Who-Watch-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/3092093096094093/The-Time-Hoppers-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/1096090093098094/At-Winter-s-End-New-Springtime-1-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/1093090097093092/The-Face-of-the-Waters-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/4098094099099091/Hawksbill-Station-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/2094099096092/The-Secret-Sharer-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/4099096097096091/The-Girl-in-the-Glass-Tower-b