Malicious PDF — malware analysis report

Static analysis result for SHA-256 da0e2f5a19e64d21…

MALICIOUS

PDF

17.7 KB Created: 2019-04-30 17:18:50 +01:00 Authoring application: mPDF 5.7
MD5: 1bb7c0f12cf851244e4ff9b2b5264cd2 SHA-1: 073fee1d1cb68c5db4f1eed944063d89328e4042 SHA-256: da0e2f5a19e64d21baeeaba79d84450150031467d95bc7db7617a24d1640883f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF_SEO_LINK_FARM heuristic indicates a large number of embedded links, suggesting a malicious distribution or SEO manipulation tactic. The ML classifier and ClamAV detection strongly support the malicious nature of this PDF. The embedded URLs, while marked as confirmed_benign in this specific report, are part of a pattern indicative of a dropper or downloader, aiming to redirect the user to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-9495678-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9495678-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5093098096095/The-Curious-Case-of-the-Clockwork-Man-Burton-amp-Swinburne-2-by-Mark-Hodder.pdf
    • http://loaminoo.linkpc.net/1090093098090093/The-Return-of-the-Discontinued-Man-Burton-amp-Swinburne-5-by-Mark-Hodder.pdf
    • http://loaminoo.linkpc.net/3097091099093095/The-Secret-of-Abdu-El-Yezdi-Burton-amp-Swinburne-4-by-Mark-Hodder.pdf
    • http://loaminoo.linkpc.net/1090093097093097/The-Secret-of-Abdu-El-Yezdi-Burton-amp-Swinburne-5-by-Mark-Hodder.pdf
    • http://loaminoo.linkpc.net/3092098099099099/The-Strange-Affair-of-Spring-Heeled-Jack-Burton-amp-Swinburne-1-by-Mark-Hodder.pdf
    • http://loaminoo.linkpc.net/3097093097093/The-Strange-Affair-of-Spring-Heeled-Jack-Burton-amp-Swinburne-1-by-Mark-Hodder.pdf
    • http://loaminoo.linkpc.net/3094090092099/Clockwork-Angel-Clockwork-Prince-Clockwork-Princess-The-Infernal-Devices-1-3-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/1092091092095097/The-Curious-Case-of-Mary-Ann-by-Jenn-Thorson.pdf
    • http://loaminoo.linkpc.net/2093090094096093/The-Curious-Case-of-Benjamin-Button-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/2097096094090092/The-Curious-Case-Of-Benjamin-Button-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/4094099093097091/The-Curious-Case-of-the-Scientist-and-the-Bimbo-by-Nadia-Nightside.pdf
    • http://loaminoo.linkpc.net/1093096097099098/The-Curious-Case-of-Dassoukine-s-Trousers-by-Fouad-Laroui.pdf
    • http://loaminoo.linkpc.net/8092095094094094/The-Case-of-the-Curious-Bride-by-Erle-Stanley-Gardner.pdf
    • http://loaminoo.linkpc.net/2096097098097098/The-Curious-Case-of-Benjamin-Button-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/3094099090097098/The-Man-From-U-N-D-E-A-D---The-Curious-Case-Of-The-Kidnapped-Chemist-by-Darren-Humphries.pdf
    • http://loaminoo.linkpc.net/6098093096091098/The-Curious-Case-of-Benjamin-Button-and-Six-Other-Stories-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/4096097092098092/The-Curious-Case-of-Lady-Latimer-s-Shoes-by-Stephanie-Laurens.pdf
    • http://loaminoo.linkpc.net/5098096097099095/The-Curious-Case-of-Benjamin-Button-HCR104fm-Edition-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/2090096098090099/The-Curious-Case-of-the-Werewolf-That-Wasn-t-Parasol-Protectorate-0-5-by-Gail-Carriger.pdf
    • http://loaminoo.linkpc.net/3092091091095098/The-Curious-Case-of-Lady-Latimer-s-Shoes-A-Casebook-of-Barnaby-Adair-Novel-by-Stephanie-Laurens.pdf