Malicious PDF — malware analysis report

Static analysis result for SHA-256 1a0c6ab9a7b11f6f…

MALICIOUS

PDF

16.6 KB Created: 2019-04-30 05:18:09 +01:00 Authoring application: mPDF 5.7
MD5: c280e8b2830dbba175d6ed4162971bd2 SHA-1: 8fdf9005dc6f63013935ffb8e6bc3f0d2d8f95f1 SHA-256: 1a0c6ab9a7b11f6f607b3d820d691ca1c0a615de4e60f7028e46cb5dbd28281b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDFs, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure and link farm heuristic suggest a delivery mechanism for potentially harmful content, possibly related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2094097092099095/Gold-Rush-Phoebe-The-Petticoat-Party-4-by-Kathleen-Karr.pdf
    • http://loaminoo.linkpc.net/7093091098098/Yukon-Gold-The-Story-of-the-Klondike-Gold-Rush-by-Charlotte-Foltz-Jones.pdf
    • http://loaminoo.linkpc.net/1090091096099091096/Gold-The-Story-of-the-1848-Gold-Rush-and-How-It-Shaped-a-Nation-by-Fred-Rosen.pdf
    • http://loaminoo.linkpc.net/3096097099097096/The-Age-of-Gold-The-California-Gold-Rush-and-the-New-American-Dream-by-H-W-Brands.pdf
    • http://loaminoo.linkpc.net/1091098090092091097/The-Boxer-by-Kathleen-Karr.pdf
    • http://loaminoo.linkpc.net/1091094097097098096/Exiled-Memoirs-of-a-Camel-by-Kathleen-Karr.pdf
    • http://loaminoo.linkpc.net/5090090092092098/Mama-Went-to-Jail-for-the-Vote-by-Kathleen-Karr.pdf
    • http://loaminoo.linkpc.net/3094095097095099/Gold-Rush-by-Jordan-Lynde.pdf
    • http://loaminoo.linkpc.net/3094095097098096/Blacks-in-Gold-Rush-California-by-Richard-M-Lapp.pdf
    • http://loaminoo.linkpc.net/2092096090098097/Rush-for-the-Gold-Mystery-at-the-Olympics-by-John-Feinstein.pdf
    • http://loaminoo.linkpc.net/3094095090098090/Gold-Rush-Brides-Emmy-by-Cassie-Hayes.pdf
    • http://loaminoo.linkpc.net/8090098093094095/A-Rush-of-Gold-to-the-Head-Fortune-Out-West-1-by-K-L-Hemley.pdf
    • http://loaminoo.linkpc.net/1096092091098099/Gold-Rush-Girl-The-California-Argonauts-1-by-Suzanne-Lilly.pdf
    • http://loaminoo.linkpc.net/1091093093093096097/The-Blue-Parka-Man-Alaskan-Gold-Rush-Bandit-by-H-C-Landru.pdf
    • http://loaminoo.linkpc.net/3093099090097095/The-California-Gold-Rush-and-the-Coming-of-the-Civil-War-by-Leonard-L-Richards.pdf
    • http://loaminoo.linkpc.net/2092096098097099/Echo-Chamber-Rush-Limbaugh-and-the-Conservative-Media-Establishment-by-Kathleen-Hall-Jamieson.pdf
    • http://loaminoo.linkpc.net/1095097091090098/The-Great-Ocean-Pacific-Worlds-from-Captain-Cook-to-the-Gold-Rush-by-David-Igler.pdf
    • http://loaminoo.linkpc.net/1094093095094093/Digger-The-Tragic-Fate-of-the-California-Indians-from-the-Missions-to-the-Gold-Rush-by-Jerry-Stanley.pdf
    • http://loaminoo.linkpc.net/2099094096091/Precious-Dust-The-American-Gold-Rush-Era-1848-1900-by-Paula-Mitchell-Marks.pdf
    • http://loaminoo.linkpc.net/1090097093091096093/Strands-of-Gold-by-Kathleen-Morgan.pdf