Malicious PDF — malware analysis report

Static analysis result for SHA-256 e643222bd4a1c827…

MALICIOUS

PDF

15.5 KB Created: 2019-04-30 04:58:20 +01:00 Authoring application: mPDF 5.7
MD5: b9c168900e9f8780c755c294b7383c50 SHA-1: fcc4fb00534143d1794703029b965828e2791968 SHA-256: e643222bd4a1c827bfe44a018a2a7b4a8bea94ada8630b46d0b4fa96bf3a29a6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, a technique commonly used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The embedded links, while labeled as benign by reputation services, are part of a link farm designed to direct users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9091098092090/Tears-of-Glass-by-David-Lake.pdf
    • http://loaminoo.linkpc.net/5096090094096/Tears-of-Glass-by-David-Lake.pdf
    • http://loaminoo.linkpc.net/8098091091095/The-Lake-of-Tears-Deltora-Quest-2-by-Emily-Rodda.pdf
    • http://loaminoo.linkpc.net/1090096090093094092/Etched-in-Tears-A-Webb-s-Glass-Shop-Mystery-4-by-Cheryl-Hollon.pdf
    • http://loaminoo.linkpc.net/3094090094096/The-Glass-Lake-by-Maeve-Binchy.pdf
    • http://loaminoo.linkpc.net/8095098093095093/Lilith-s-Tears-and-the-Travelling-Circus-of-Lacrimosa-by-David-Jones.pdf
    • http://loaminoo.linkpc.net/7091090096092/Tears-Of-Passion-Tears-Of-Shame-by-Graham-Diamond.pdf
    • http://loaminoo.linkpc.net/1091097093091094093/Margot-Cranston-the-Mystery-at-Loon-Lake-by-David-W-Menefee.pdf
    • http://loaminoo.linkpc.net/2099098091099095/Library-Looking-Glass-A-Personal-Anthology-by-David-Cecil.pdf
    • http://loaminoo.linkpc.net/1095097091098095/Lords-of-the-Lake-The-Naval-War-on-Lake-Ontario-1812-1814-by-Robert-Malcomson.pdf
    • http://loaminoo.linkpc.net/4090098090097097/The-Lake-Regions-of-Central-Africa-Volume-I-from-Zanzibar-to-Lake-Tanganyika-by-Richard-Francis-Burton.pdf
    • http://loaminoo.linkpc.net/5090092094096/Lake-Chelan-The-Greatest-Lake-In-The-World-by-John-Fahey.pdf
    • http://loaminoo.linkpc.net/5091099094099/Beneath-the-Lake-Lake-Lanier-Mysteries-1-by-Casi-McLean.pdf
    • http://loaminoo.linkpc.net/6099091095094098/A-Night-at-Tears-of-Crimson-Tears-of-Crimson-1-by-Michelle-Hughes.pdf
    • http://loaminoo.linkpc.net/2098090091098094/The-Lake-The-Lake-Trilogy-1-by-AnnaLisa-Grant.pdf
    • http://loaminoo.linkpc.net/6097095099094/Girl-Under-Glass-Glass-and-Iron-1-by-Monica-Enderle-Pierce.pdf
    • http://loaminoo.linkpc.net/4094093098094094/Shards-of-Glass-The-Glass-Trilogy-1-by-Arianne-Richmonde.pdf
    • http://loaminoo.linkpc.net/9098093091097098/Moon-Lake-Hate-Ghost-Trouble-Witch-Rescue-Moon-Lake-Mystery-6-by-Lucia-Kuhl.pdf
    • http://loaminoo.linkpc.net/8095097097099096/Maligne-Lake-Safety-Book-The-Essential-Lake-Safety-Guide-for-Children-by-Jobe-Leonard.pdf
    • http://loaminoo.linkpc.net/1099096092099097/Through-Glass-Episode-One-Through-Glass-1-by-Rebecca-Ethington.pdf
    • http://loaminoo.linkpc.net/5090092094096/Lake-Chelan-The-Greatest-Lak