Malicious PDF — malware analysis report

Static analysis result for SHA-256 2838d4eaf1c312a3…

MALICIOUS

PDF

15.4 KB Created: 2019-05-14 15:41:49 +01:00 Authoring application: mPDF 5.7
MD5: 1654d35ad189ca05c6e8f1b721484e12 SHA-1: abcb0bfa1f3cf0a9d7f94af0c16d3fa614df5320 SHA-256: 2838d4eaf1c312a32663d0edd6216ccabefc77927f9a32b8608e2173f81ffacf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a link farm designed to direct users to potentially malicious content or phishing sites. The ML_NYX_PDF_MALICIOUS classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6090092094093091/Andr-e-s-Story-the-Complete-Record-of-His-Polar-Flight-1897-by-S-A-Andr-e.pdf
    • http://loaminoo.linkpc.net/1096098098096099/Lithochronos-Ou-Le-Premier-Vol-de-La-Pierre-Autour-de-Quinze-Photographies-D-Andree-Christensen-by-Andr-e-Christensen.pdf
    • http://loaminoo.linkpc.net/5098090096096094/Selected-Poems-of-Andree-Chedid-by-Andr-e-Chedid.pdf
    • http://loaminoo.linkpc.net/5095090096092095/A-Wild-Sheep-Chase-Dance-Dance-Dance-The-Rat-3-4-by-Haruki-Murakami.pdf
    • http://loaminoo.linkpc.net/4092091097097092/The-Boy-with-17-Senses-by-Sheila-Grau.pdf
    • http://loaminoo.linkpc.net/7098094093094093/Conesa-by-Josep-M-T-Grau-I-Pujol.pdf
    • http://loaminoo.linkpc.net/2094090091097093/The-Keepers-of-the-House-by-Shirley-Ann-Grau.pdf
    • http://loaminoo.linkpc.net/3093095090095/Dance-Dance-Dance-The-Rat-4-by-Haruki-Murakami.pdf
    • http://loaminoo.linkpc.net/8090096091090/Grau-Ein-Eddie-Russett-Roman-Shades-of-Grey-1-by-Jasper-Fforde.pdf
    • http://loaminoo.linkpc.net/1090098094095092094/The-Bear-Went-Over-the-Mountain-Soviet-Combat-Tactics-in-Afghanistan-by-Lester-W-Grau.pdf
    • http://loaminoo.linkpc.net/4094097096098099/Dance-a-While-A-Handbook-for-Folk-Square-Contra-and-Social-Dance-by-Anne-M-Pittman.pdf
    • http://loaminoo.linkpc.net/4099090095097097/Dying-To-Dance-A-Maddie-Fitzpatrick-Dance-Mystery-by-Kate-O-39-Connell.pdf
    • http://loaminoo.linkpc.net/6092099091099097/Going-for-a-Sea-Bath-by-Andr-e-Poulin.pdf
    • http://loaminoo.linkpc.net/9099093096099091/Frances-Dean-Who-Loved-to-Dance-and-Dance-by-Birgitta-Sif.pdf
    • http://loaminoo.linkpc.net/1099094099093092/Dance-of-Fire-Dance-of-Shadows-2-by-Yelena-Black.pdf
    • http://loaminoo.linkpc.net/6092099093091091/The-Magic-Clothesline-by-Andr-e-Poulin.pdf
    • http://loaminoo.linkpc.net/6090092097093096/366-and-More-Wonders-of-the-World-by-Andree-Bertino.pdf
    • http://loaminoo.linkpc.net/6090092094098098/Balenciaga-by-Marie-Andr-e-Jouve.pdf
    • http://loaminoo.linkpc.net/6090092094097095/Every-Little-Girl-is-a-Princess-by-Andree-Prendergast.pdf
    • http://loaminoo.linkpc.net/6090092094093096/When-the-Anger-Ogre-Visits-by-Andree-Salom.pdf
    • http://loaminoo.linkpc.net/3093095090095/Dance