Malicious PDF — malware analysis report

Static analysis result for SHA-256 305acd71783a692e…

MALICIOUS

PDF

22.8 KB Created: 2019-04-30 18:38:25 +01:00 Authoring application: mPDF 5.7
MD5: ec333accc88f82bcac1ea7d2630427f4 SHA-1: bc74d154214b0616ac37c61ef1e8f4a668e0698e SHA-256: 305acd71783a692ef24c1343d0097769681713baf66f84eea19cc41c34ed4e6b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links were classified as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS firing suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093099094099091/Ancient-Treasures-The-Discovery-of-Lost-Hoards-Sunken-Ships-Buried-Vaults-and-Other-Long-Forgotten-Artifacts-by-Brian-Haughton.pdf
    • http://loaminoo.linkpc.net/1096097098091094/Hidden-History-Lost-Civilizations-Secret-Knowledge-and-Ancient-Mysteries-by-Brian-Haughton.pdf
    • http://loaminoo.linkpc.net/4091097092099096/Little-Owl-Lost-by-Chris-Haughton.pdf
    • http://loaminoo.linkpc.net/3090095092097097/Treasures-Lost-Treasures-Found-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/2097099098091092/Lustmord-The-Writings-and-Artifacts-of-Murderers-by-Brian-King.pdf
    • http://loaminoo.linkpc.net/7095092095096096/The-Treasures-of-Ancient-Egypt-From-the-Rosetta-Stone-to-the-Tomb-of-Tutankhamun---The-Search-for-the-Riches-of-Ancient-Egypt-by-Jaromir-Malek.pdf
    • http://loaminoo.linkpc.net/4099097097090093/The-Seventh-Magic-Artifacts-of-Power-Trilogy-3-by-Brian-Rathbone.pdf
    • http://loaminoo.linkpc.net/1091098092098099/Forgotten-Treasures-by-B-M-Killaire.pdf
    • http://loaminoo.linkpc.net/2095090090093097/The-Long-Ships-by-Frans-G-Bengtsson.pdf
    • http://loaminoo.linkpc.net/9099094095094091/Star-Wars-Fanon---Capital-Ships-Lucrehulk-Class-Battleships-New-Republic-Capital-Ships-Republic-Capital-Ships-Star-Destroyers-True-Republic-Capital-Ships-Astraeus-Class-Battleship-Contessa-Entarian-Olean-Erebos-Esvelde-Federation-Swarm-Freedom-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/9095092095096092/The-Treasures-of-Ancient-Egypt-by-The-Egyptian-Museum-In-Cairo.pdf
    • http://loaminoo.linkpc.net/5090092094095096/The-Complete-Valley-of-the-Kings-Tombs-and-Treasures-of-Ancient-Egypt-s-Royal-Burial-Site-by-Nicholas-Reeves.pdf
    • http://loaminoo.linkpc.net/1095092093098092/The-Lost-Years-of-Mehy-Treasures-of-the-Nile-1-5-by-Mesu-Andrews.pdf
    • http://loaminoo.linkpc.net/1093097096095093/Nabokov-s-Pale-Fire-The-Magic-of-Artistic-Discovery-by-Brian-Boyd.pdf
    • http://loaminoo.linkpc.net/2095098094098098/Fish-on-Friday-Feasting-Fasting-and-the-Discovery-of-the-New-World-by-Brian-M-Fagan.pdf
    • http://loaminoo.linkpc.net/1097090096091092/Lost-and-Found-Discovery-1-by-Megan-Fields.pdf
    • http://loaminoo.linkpc.net/4090090096099097/The-Teddy-Bear-Habit-Lost-Treasures-3-by-James-Lincoln-Collier.pdf
    • http://loaminoo.linkpc.net/1093095092093099/Cruise-Confidential-A-Hit-Below-the-Waterline-Where-the-Crew-Lives-Eats-Wars-and-Parties-One-Crazy-Year-Working-on-Cruise-Ships-by-Brian-David-Bruns.pdf
    • http://loaminoo.linkpc.net/6098090091092090/Forgotten-Stones-Ancient-Church-Sites-of-the-Burren-amp-Environs-by-Averil-Swinfen.pdf
    • http://loaminoo.linkpc.net/4091099090096094/Lost-amp-Forgotten-by-James-R-Paddock.pdf
    • http://loaminoo.linkpc.net/409909