Malicious PDF — malware analysis report

Static analysis result for SHA-256 30de6964b5068cd4…

MALICIOUS

PDF

16.9 KB Created: 2019-05-04 13:24:32 +01:00 Authoring application: mPDF 5.7
MD5: bef20d33410b2b6b9f26e778e3e56786 SHA-1: 6f15336bc3dad9b4ed94948dd7b1efb3757a04db SHA-256: 30de6964b5068cd4eee89e32336abc278e09383463d7eb273838ecf51ff5fadb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The document body consists of these links, suggesting a lure to distribute potentially malicious content or engage in SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1095099090099093/The-Twelve-Dates-of-Christmas-by-Catherine-Hapka.pdf
    • http://loaminoo.linkpc.net/1095099091092099/Winter-s-Kiss-The-Ex-Games-The-Twelve-Dates-of-Christmas-by-Jennifer-Echols.pdf
    • http://loaminoo.linkpc.net/1091094092090095097/A-Heartwarming-Christmas-A-Boxed-Set-of-Twelve-Sweet-Holiday-Romances-Christmas-Town-Maine-2-5-by-Melinda-Curtis.pdf
    • http://loaminoo.linkpc.net/4097099094093099/The-Billionaire-s-Baby-SOS-The-Larkville-Legacy-8-by-Susan-Meier.pdf
    • http://loaminoo.linkpc.net/1097094094094094/Her-Summer-with-the-Marine-The-Donovan-Brothers-1-by-Susan-Meier.pdf
    • http://loaminoo.linkpc.net/4098091090095099/candy-canes-of-christmas-past-by-Leslie-Meier.pdf
    • http://loaminoo.linkpc.net/4095091094098091/Head-Over-Heels-for-the-Boss-The-Donovan-Brothers-3-by-Susan-Meier.pdf
    • http://loaminoo.linkpc.net/1090090093097091099/Zig-Meier-und-die-Grube-von-Walden-Zbigniew-Meier-3-by-Stephan-Br-ggenthies.pdf
    • http://loaminoo.linkpc.net/2098090096095094/Dates-Double-Dates-and-Big-Big-Trouble-Ally-s-World-2-by-Karen-McCombie.pdf
    • http://loaminoo.linkpc.net/4091096091099099/The-Twelve-Days-of-Christmas-by-Laurel-Long.pdf
    • http://loaminoo.linkpc.net/7096098090093093/Anansi-and-the-Twelve-Days-of-Christmas-by-Gillena-Cox.pdf
    • http://loaminoo.linkpc.net/4099091094099093/The-Christmas-Tree-Bride-The-12-Brides-of-Christmas-8-by-Susan-Page-Davis.pdf
    • http://loaminoo.linkpc.net/9099099098099091/Stadhuis-Bibliotheek-the-City-Hall-Library-Complex-by-Richard-Meier-in-the-Hague-by-Richard-Meier.pdf
    • http://loaminoo.linkpc.net/1095099091091092/Twelve-Ways-To-Spend-One-s-Christmas-Eve-by-Mariam-Razek.pdf
    • http://loaminoo.linkpc.net/3093091095099093/The-Twelve-Days-of-Christmas-in-South-Carolina-by-Melinda-Long.pdf
    • http://loaminoo.linkpc.net/2096097092099099/Twelve-Drummers-Drumming-Father-Christmas-Mystery-1-by-C-C-Benison.pdf
    • http://loaminoo.linkpc.net/1098091090099096/Mates-Dates-and-Inflatable-Bras-Mates-Dates-1-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/1098091090095093/Mates-Dates-and-Sizzling-Summers-Mates-Dates-12-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/2098090094099096/Mates-Dates-and-Chocolate-Cheats-Mates-Dates-10-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/5090091091094093/Mates-Dates-and-Diamond-Destiny-Mates-Dates-11-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/709609