Malicious PDF — malware analysis report

Static analysis result for SHA-256 087662e1a2458d0d…

MALICIOUS

PDF

14.8 KB Created: 2019-05-01 19:27:58 +01:00 Authoring application: mPDF 5.7
MD5: 66110e5663d2f78fcfc6656e0e02590f SHA-1: f59fd81a1c07f34fb80017b63bf74f3837f7584a SHA-256: 087662e1a2458d0d4c1e688c0ee5982c8b79ecb85c04c163f915c978498b6d12
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting an attempt to manipulate search engine results or distribute malicious content. While the ML_NYX_PDF_MALICIOUS heuristic indicates a high probability of maliciousness, the specific intent beyond link distribution is unclear due to the obfuscated document body. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4095095095095092/Totally-Toned-Arms-Get-Michelle-Obama-Arms-in-21-Days-by-Rylan-Duggan.pdf
    • http://loaminoo.linkpc.net/8091090094099095/ARMS-Harris-Revenge-ARMS-2-by-Stephen-Arseneault.pdf
    • http://loaminoo.linkpc.net/8091090095095099/ARMS-For-Eternity-ARMS-8-by-Stephen-Arseneault.pdf
    • http://loaminoo.linkpc.net/7097097097097099/Tyson-Caine-Brothers-in-Arms-1-by-Aleya-Michelle.pdf
    • http://loaminoo.linkpc.net/2091091092098096/In-the-Arms-of-a-Pirate-A-Sam-Steele-Romance-Book-2-by-Michelle-Beattie.pdf
    • http://loaminoo.linkpc.net/4092098097091090/Michelle-Obama-Speeches-on-Life-Love-and-American-Values-by-Michelle-Obama.pdf
    • http://loaminoo.linkpc.net/7093096098095096/Tanned-Toned-and-Totally-Faking-It-by-Whitney-Boyd.pdf
    • http://loaminoo.linkpc.net/1095097090096091/Martian-Summer-Robot-Arms-Cowboy-Spacemen-and-My-90-Days-with-the-Phoenix-Mars-Mission-by-Andrew-Kessler.pdf
    • http://loaminoo.linkpc.net/5091095092094/The-Man-with-Two-Arms-by-Billy-Lombardo.pdf
    • http://loaminoo.linkpc.net/2094098096099091/In-the-Arms-of-the-Enemy-by-Lisbeth-Eng.pdf
    • http://loaminoo.linkpc.net/7097095095091099/The-Boy-in-My-Arms-by-Madame-Bijoux.pdf
    • http://loaminoo.linkpc.net/1097098096091099/Up-in-Arms-by-Kindle-Alexander.pdf
    • http://loaminoo.linkpc.net/1091090094090092093/In-His-Arms-by-Lisa-Erler.pdf
    • http://loaminoo.linkpc.net/3099098090093091/In-Your-Arms-by-Merry-Farmer.pdf
    • http://loaminoo.linkpc.net/9096093094097095/The-Arms-Of-Morpheus-by-Sean-Ivory.pdf
    • http://loaminoo.linkpc.net/1096095098092096/A-Trophy-of-Arms-by-Ruth-Pitter.pdf
    • http://loaminoo.linkpc.net/2097097099092097/Lovers-in-Arms-by-Osiris-Brackhaus.pdf
    • http://loaminoo.linkpc.net/1099098099097099/Arms-Wide-Open-by-Tom-Winter.pdf
    • http://loaminoo.linkpc.net/1096093095098091/Empty-Arms-by-Erika-Liodice.pdf
    • http://loaminoo.linkpc.net/2090093093095093/One-Night-In-His-Arms-by-Penny-Jordan.pdf