Malicious PDF — malware analysis report

Static analysis result for SHA-256 1baeaa0ef827c080…

MALICIOUS

PDF

12.2 KB Created: 2019-05-03 14:37:03 +01:00 Authoring application: mPDF 5.7
MD5: dff43c2b37daf49acd13540396503c72 SHA-1: 15267f4d51684eeeb4c6a8a5c2601ac982be8573 SHA-256: 1baeaa0ef827c080854625c7d7a44c5d93ebb1f89c197be8d6e0aa42569a7d88
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. The embedded URLs likely serve as a distribution mechanism for malicious content, such as malware or phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8780

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4094099093095094/Ten-Beach-Road-Ten-Beach-Road-1-by-Wendy-Wax.pdf
    • http://loaminoo.linkpc.net/3093095097099098/Ten-Beach-Road-Ten-Beach-Road-1-by-Wendy-Wax.pdf
    • http://loaminoo.linkpc.net/3099095091099094/The-House-on-Mermaid-Point-Ten-Beach-Road-3-by-Wendy-Wax.pdf
    • http://loaminoo.linkpc.net/1098096098097099/Now-You-See-Her-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/2099095091/NYPD-Red-4-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1091099093094098096/Hunted-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/2095092094092093/The-Games-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/4094095098093097/The-Big-Bad-Wolf-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/7091094096092/Kill-Me-if-You-Can-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/2098091095094094/First-Love-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/6097098094091097/Qui-a-tu-Toutankhamon-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/4090097095095/You-ve-Been-Warned-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1092096099090092/Toys-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/8092099098095097/The-Chef-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/4090093093/Woman-of-God-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/3098097094097096/The-Shut-In-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1092093090097098/First-Love-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/5095097097094/Invisible-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/2096096092094092/Cradle-and-All-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/4097098094092094/The-8th-Confession-by-James-Patterson.pdf