Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f64edf0fe7be595…

MALICIOUS

PDF

17.0 KB Created: 2019-04-30 17:26:57 +01:00 Authoring application: mPDF 5.7
MD5: ae35fccf74d0f69db5037acccbf93a20 SHA-1: 1d8c41065a34fe93fb7dfb0476a432d333216411 SHA-256: 1f64edf0fe7be59546799c8dda9aeaefbde9e5e7b5400f82772e58463727039c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. The ML_NYX_PDF_MALICIOUS classifier also flagged this file with high confidence. While no scripts were extracted, the structure and heuristics point towards a malicious PDF designed to redirect users to external content, potentially for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1093096098093090/Beloved-Prophet-The-Love-Letters-of-Kahlil-Gibran-and-Mary-Haskell-and-Her-Private-Journal-by-Mary-Elizabeth-Haskell.pdf
    • http://loaminoo.linkpc.net/3090099093098099/Love-Letters-The-Love-Letters-of-Kahlil-Gibran-to-May-Ziadah-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/8099096093099094/Don-Carlos-Mary-Stuart-the-Robbers-Fiesco-Love-and-Intrigue-Volume-3-by-Nathan-Haskell-Dole.pdf
    • http://loaminoo.linkpc.net/1099091094099091/Das-gro-e-Khalil-Gibran-Lesebuchmit-seinem-Bekanntesten-Buch-der-Prophet-in-der-U-bersetzung-von-Georg-Eduard-Freiherr-von-Stietencron-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/5090093096095096/The-Prophet-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/3092092094096/The-Prophet-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/1093099097096091/The-Prophet-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/7097091092091092/The-Broken-Wings-Khalil-Gibran-Sphinx-Books-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/9098097091093/The-Wisdom-of-Kahlil-Gibran-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/3099092090092098/The-Khalil-Gibran-Collection-Volume-III-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/3094098093095094/True-Love-Way-by-Mary-Elizabeth.pdf
    • http://loaminoo.linkpc.net/1094093094090093/Darwin-With-Glimpses-into-His-Private-Journal-and-Letters-by-Alice-B-McGinty.pdf
    • http://loaminoo.linkpc.net/3095090097091096/Kidnapped-in-Key-West-by-Susan-Haskell.pdf
    • http://loaminoo.linkpc.net/3096099090095097/The-Gold-Club-by-David-Haskell.pdf
    • http://loaminoo.linkpc.net/3096092094099097/Moist-by-Mark-Haskell-Smith.pdf
    • http://loaminoo.linkpc.net/4094099097092/The-Madman-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/5093097099093090/Story-of-the-Seer-of-Patmos-by-Stephen-Haskell.pdf
    • http://loaminoo.linkpc.net/3090093093090095/Sand-and-Foam-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/1090092097092098/Sand-and-Foam-by-Kahlil-Gibran.pdf
    • http://loaminoo.linkpc.net/7091091096099098/Steven-Spielberg-A-Life-in-Films-by-Molly-Haskell.pdf
    • http://loaminoo.linkpc.net/1099091094099091/Das-gro-e-Khalil-Gibran-Lesebuchmit-seinem-Bekanntesten-Buch-der-Prophet-in-der-U-bersetzung-von-Georg-Eduard-Freiherr-von-Stiete