Malicious PDF — malware analysis report

Static analysis result for SHA-256 2731c577fab18b04…

MALICIOUS

PDF

20.9 KB Created: 2019-04-30 02:25:23 +01:00 Authoring application: mPDF 5.7
MD5: e0a1f9067e9afac5c9984654c7a74141 SHA-1: 47d465106dcdd48d613f72c7fe6065afed187d5a SHA-256: 2731c577fab18b04c447435f933e8808bf2017ed22028676e89de46b0bc33bef
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4095093097094099/What-Do-You-think-of-Me-Why-Do-I-Care-Answers-to-the-Big-Questions-of-Life-by-Edward-T-Welch.pdf
    • http://loaminoo.linkpc.net/7095093094097/A-Modern-Prophet-Answers-Your-Key-Questions-about-Life-by-Harold-Klemp.pdf
    • http://loaminoo.linkpc.net/2099097099095098/Mystery-and-Crime-The-New-York-Public-Library-Book-of-Answers-Intriguing-and-Entertaining-Questions-and-Answers-About-the-Who-s-Who-and-Whats-s-by-Jay-Pearsall.pdf
    • http://loaminoo.linkpc.net/2092098099091092/After-Life-Answers-from-the-Other-Side-by-John-Edward.pdf
    • http://loaminoo.linkpc.net/1091098092096091093/What-is-Heaven-Really-Like-Biblical-answers-to-the-10-biggest-questions-about-life-after-death-Spiritual-Growth-by-John-Stange-Book-3-by-John-Stange.pdf
    • http://loaminoo.linkpc.net/9090091098/Brief-Answers-to-the-Big-Questions-by-Stephen-Hawking.pdf
    • http://loaminoo.linkpc.net/3094094095097097/Questions-and-Answers-about-Weather-by-M-Jean-Craig.pdf
    • http://loaminoo.linkpc.net/6099099094092097/Essentials-of-NLP-150-Questions-amp-Answers-by-Shlomo-Vaknin.pdf
    • http://loaminoo.linkpc.net/8091090093095/The-New-Answers-Book-4-Over-30-Questions-on-Evolution-Creation-and-the-Bible-by-Ken-Ham.pdf
    • http://loaminoo.linkpc.net/4095096092090/The-New-Answers-Book-1-Over-25-Questions-on-Creation-Evolution-and-the-Bible-by-Ken-Ham.pdf
    • http://loaminoo.linkpc.net/9099095092096095/Asthma-Questions-You-Have-Answers-You-Need-by-Paula-Brisco-Dr-Robert-Youngson.pdf
    • http://loaminoo.linkpc.net/1091094099097096099/Multiple-Sclerosis-5th-Edition-The-Questions-You-Have-The-Answers-You-Need-by-Rosalind-C-Kalb.pdf
    • http://loaminoo.linkpc.net/1090091091090/What-If-Serious-Scientific-Answers-to-Absurd-Hypothetical-Questions-by-Randall-Munroe.pdf
    • http://loaminoo.linkpc.net/2095099092092094/Great-Answers-To-Tough-Interview-Questions-by-Martin-Yate.pdf
    • http://loaminoo.linkpc.net/1091093090093091091/The-250-Job-Interview-Questions-You-ll-Most-Likely-Be-Asked-and-the-Answers-That-Will-Get-You-Hired-by-Peter-Veruki.pdf
    • http://loaminoo.linkpc.net/7092094099091/Heaven-Biblical-Answers-to-Common-Questions-by-Randy-Alcorn.pdf
    • http://loaminoo.linkpc.net/5098098090092/What-If-Serious-Scientific-Answers-to-Absurd-Hypothetical-Questions-by-Randall-Munroe.pdf
    • http://loaminoo.linkpc.net/8096090096092094/Does-It-Really-Rain-Frogs-Questions-and-Answers-about-Planet-Earth-by-Thomas-Canavan-Jr-.pdf
    • http://loaminoo.linkpc.net/2093092099099094/100-Questions-amp-Answers-about-Stroke-A-Lahey-Clinic-Guide-by-Kinan-K-Hreib.pdf
    • http://loaminoo.linkpc.net/8097099090092090/A-Chicken-Followed-Me-Home-Questions-and-Answers-about-a-Familiar-Fowl-by-Robin-Page.pdf
    • http://loaminoo.linkpc.net/1091098092096091093/What-is-Heaven-Really-Like-Biblical-answe