Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f69215944f72e95…

MALICIOUS

PDF

18.7 KB Created: 2019-05-02 18:47:17 +01:00 Authoring application: mPDF 5.7
MD5: fb8ac3f121ea89c5c5fb984b2164f3e8 SHA-1: fa0bd5ec4aa0ed2fde9e2ad0ce2f82ea25bf2c64 SHA-256: 1f69215944f72e95e1d313447c7df7a90ebfcceddab1ded98f9a159ba22453b2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern appears to be directing users to a multitude of external URLs, likely for SEO spam or to serve further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9951

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5094096094090093/Rough-Cut-Black-and-White-Collection-3-by-Mari-Carr.pdf
    • http://loaminoo.linkpc.net/1091091095093098095/Slam-Dunk-Black-and-White-Collection-6-by-Mari-Carr.pdf
    • http://loaminoo.linkpc.net/1093094094096095/Golden-Filly-Collection-1-by-Lauraine-Snelling.pdf
    • http://loaminoo.linkpc.net/1091092097093090091/Morocco-Bonechi-Golden-Book-Collection-by-Anna-Baldini.pdf
    • http://loaminoo.linkpc.net/2094090094096/Arthur-and-the-Golden-Rope-The-Brownstone-s-Mythical-Collection-1-by-Joe-Todd-Stanton.pdf
    • http://loaminoo.linkpc.net/5097090093098090/Allen-Carr-s-Easyweigh-to-Lose-Weight-by-Allen-Carr.pdf
    • http://loaminoo.linkpc.net/2098091096090097/Dreams-of-the-Golden-Age-Golden-Age-2-by-Carrie-Vaughn.pdf
    • http://loaminoo.linkpc.net/1094091095091098/The-Golden-Transcendence-Golden-Age-3-by-John-C-Wright.pdf
    • http://loaminoo.linkpc.net/1099095091092099/Golden-Golden-1-by-Melinda-Michaels.pdf
    • http://loaminoo.linkpc.net/7094091094097093/The-Complete-Golden-Dawn-Cipher-Manuscript-Golden-Dawn-Studies-No-1-by-Darcy-Kuntz.pdf
    • http://loaminoo.linkpc.net/8095093096091091/Golden-Boys-4-1-Yoan-Golden-Boys-4-1-by-Fleur-Hana.pdf
    • http://loaminoo.linkpc.net/6099094096096090/The-John-Dickson-Carr-Treasury-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/6097099093097/Golden-Shadows-Shadows-Golden-Under-the-Sun-by-Amitava-Mazumdar.pdf
    • http://loaminoo.linkpc.net/3091096099097096/The-Golden-City-The-Golden-City-1-by-J-Kathleen-Cheney.pdf
    • http://loaminoo.linkpc.net/9091096093099099/The-Girl-With-The-Golden-Spurs-Golden-Spurs-1-by-Ann-Major.pdf
    • http://loaminoo.linkpc.net/1091094092099090092/Catalogue-of-the-Collection-of-American-and-Foreign-Coins-and-Medals-Ancient-and-Modern-Formerly-the-Property-of-Mr-A-Dohrmann-of-San-Francisco-California-Also-of-a-Small-Numismatic-Library-and-a-Little-Collection-of-Union-Envelopes-by-W-Elliot-Woodward.pdf
    • http://loaminoo.linkpc.net/7097090090095092/BEN-HUR-THE-FAIR-GOD-amp-THE-PRINCE-OF-INDIA-or-Why-Constantinople-Fell-LEW-WALLACE-PREMIUM-COLLECTION-Timeless-Wisdom-Collection-Book-1825-by-Lew-Wallace.pdf
    • http://loaminoo.linkpc.net/8096092093092093/Bad-Student-by-Kam-Carr.pdf
    • http://loaminoo.linkpc.net/5092091090097094/Ace-by-Richard-Carr.pdf
    • http://loaminoo.linkpc.net/2095090093092091/Birdie-by-M-C-Carr.pdf
    • http://loaminoo.linkpc.net/80950930960