Malicious PDF — malware analysis report

Static analysis result for SHA-256 d60bfc669ef8199e…

MALICIOUS

PDF

16.7 KB Created: 2019-05-01 07:11:37 +01:00 Authoring application: mPDF 5.7
MD5: bf76e177f02a13a847f511ce49d574b7 SHA-1: 471323b4eb18a6efc700505965f347f5733b79fc SHA-256: d60bfc669ef8199e03618cfccf08aa1f9731dc955b03c269a5c214811a9bf848
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which point to external PDF files. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. The embedded URLs likely serve as a link farm to distribute or host further malicious content, potentially leading to malware downloads or phishing attempts.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3094094094093095/The-Stories-We-Tell-by-Patti-Callahan-Henry.pdf
    • http://loaminoo.linkpc.net/2098090098093098/Coming-Up-for-Air-by-Patti-Callahan-Henry.pdf
    • http://loaminoo.linkpc.net/2098090098092096/Where-the-River-Runs-by-Patti-Callahan-Henry.pdf
    • http://loaminoo.linkpc.net/8098092099097098/Delphinsommer-Roman-by-Patti-Callahan-Henry.pdf
    • http://loaminoo.linkpc.net/4096095092098090/Off-the-Wall-at-Callahan-s-Callahan-s-Series-Excerpts-and-Quotes-by-Spider-Robinson.pdf
    • http://loaminoo.linkpc.net/4096095092094099/Callahan-s-Legacy-Mary-s-Place-2-Callahan-s-7-by-Spider-Robinson.pdf
    • http://loaminoo.linkpc.net/2090092098094091/A-Callahan-Christmas-Miracle-Callahan-Cowboys-13-by-Tina-Leonard.pdf
    • http://loaminoo.linkpc.net/2090092098093098/Sweet-Callahan-Homecoming-Callahan-Cowboys-15-by-Tina-Leonard.pdf
    • http://loaminoo.linkpc.net/2090092098095099/A-Callahan-Wedding-Callahan-Cowboys-6-by-Tina-Leonard.pdf
    • http://loaminoo.linkpc.net/2099094098093097/Callahan-s-Crosstime-Saloon-Callahan-s-1-by-Spider-Robinson.pdf
    • http://loaminoo.linkpc.net/2099095099095093/The-Callahan-Chronicals-Callahan-s-1-3-by-Spider-Robinson.pdf
    • http://loaminoo.linkpc.net/7097097094096096/Patti-Labelle-s-Lite-Cuisine-by-Patti-LaBelle.pdf
    • http://loaminoo.linkpc.net/7094090098094/Principia-Discordia-Or-How-I-Found-Goddess-and-What-I-Did-to-Her-When-I-Found-Her-The-Magnum-Opiate-of-Malaclypse-the-Younger-by-Gregory-Hill.pdf
    • http://loaminoo.linkpc.net/2091091093099091/Found-Lost-amp-Found-2-by-Nadia-Simonenko.pdf
    • http://loaminoo.linkpc.net/3093099092096091/Found-at-the-Bookstore-Found-2-by-Christi-Snow.pdf
    • http://loaminoo.linkpc.net/2097092090096093/Found-at-the-Library-Found-1-by-Christi-Snow.pdf
    • http://loaminoo.linkpc.net/8096094093092091/Coreene-Callahan-Books-2017-Checklist-Reading-Order-of-Circle-of-Seven-Series-Dragonfury-Series-and-List-of-All-Coreene-Callahan-Books-by-Diamond-List.pdf
    • http://loaminoo.linkpc.net/4098093090096099/He-Found-Me-He-Found-Me-1-by-Whitney-Barbetti.pdf
    • http://loaminoo.linkpc.net/2092099092099095/Found-by-You-Found-by-You-1-by-Victoria-H-Smith.pdf
    • http://loaminoo.linkpc.net/3095094090093090/He-Found-Me-He-Found-Me-1-by-Whitney-Barbetti.pdf
    • http://loaminoo.linkpc.net/2099095099095093/The-Callahan-Chronicals-C