Malicious PDF — malware analysis report

Static analysis result for SHA-256 324dbd0b14a0555f…

MALICIOUS

PDF

24.4 KB Created: 2019-05-02 05:09:01 +01:00 Authoring application: mPDF 5.7
MD5: 396a0f37cda21d623aab763b70f4295e SHA-1: b7e8f11684bf97190ed191bd71648eaca50e119e SHA-256: 324dbd0b14a0555f3e249e2e6e4136f5301b6c8abe8b72be7ae4f3581bfc520b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents on the domain 'loaminoo.linkpc.net'. This pattern is indicative of SEO poisoning or a link farm designed to attract traffic or distribute malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090098099090098/The-Great-Escape-The-Full-Dramatic-Story-with-Contributions-from-Survivors-and-Their-Families-by-Anton-Gill.pdf
    • http://loaminoo.linkpc.net/1093093097098/Escape-The-Story-of-the-Great-Houdini-by-Sid-Fleischman.pdf
    • http://loaminoo.linkpc.net/4099090092091095/City-of-the-Horizon-by-Anton-Gill.pdf
    • http://loaminoo.linkpc.net/3093090092096098/The-Great-Arc-The-Dramatic-Tale-of-How-India-Was-Mapped-and-Everest-Was-Named-by-John-Keay.pdf
    • http://loaminoo.linkpc.net/1091098098098091094/The-Mob-Doctor-The-True-Story-That-Inspired-the-Fox-Dramatic-Serires-by-Ronald-Felber.pdf
    • http://loaminoo.linkpc.net/5090092094095094/Egypt-s-Golden-Empire-The-Dramatic-Story-of-Life-in-the-New-Kingdom-by-Joyce-A-Tyldesley.pdf
    • http://loaminoo.linkpc.net/4093092098093090/The-Quick-and-the-Dead-Fallen-Soldiers-and-Their-Families-in-the-Great-War-by-Richard-van-Emden.pdf
    • http://loaminoo.linkpc.net/1093096097093097/The-Great-Escape-by-Paul-Brickhill.pdf
    • http://loaminoo.linkpc.net/1091092090096092099/One-Hundred-Lectures-on-the-Ancient-and-Mordern-Dramatic-Poets-the-Heathen-Mythology-Oratory-and-Elocution-Down-to-the-Nineteenth-Century-Commencing-with-Thespis-the-Founder-of-the-Dramatic-Art-Sixth-Century-B-C-by-Benjamin-Charles-Jones.pdf
    • http://loaminoo.linkpc.net/3093094093093092/Emil-and-the-Great-Escape-by-Astrid-Lindgren.pdf
    • http://loaminoo.linkpc.net/3099097098093090/Astro-s-Adventures-The-Great-Escape-by-Susan-Day.pdf
    • http://loaminoo.linkpc.net/2090093090098097/Jack-of-Fables-Vol-1-The-Nearly-Great-Escape-by-Bill-Willingham.pdf
    • http://loaminoo.linkpc.net/4090097093095/In-Harm-s-Way-The-Sinking-of-the-USS-Indianapolis-and-the-Extraordinary-Story-of-Its-Survivors-by-Doug-Stanton.pdf
    • http://loaminoo.linkpc.net/1098090098092096/We-re-Three-A-Story-About-Families-And-The-Only-Child-by-Vivian-Cameron-Gallo.pdf
    • http://loaminoo.linkpc.net/6095098097095096/Alive-The-Story-of-the-Andes-Survivors-Alpha-Books-by-Piers-Paul-Read.pdf
    • http://loaminoo.linkpc.net/2090099098096098/The-Story-of-a-Nobody-by-Anton-Chekhov.pdf
    • http://loaminoo.linkpc.net/6092090090097093/Red-Families-v-Blue-Families-Legal-Polarization-and-the-Creation-of-Culture-by-Naomi-R-Cahn.pdf
    • http://loaminoo.linkpc.net/8094091094091099/A-History-and-Genealogy-of-the-Families-of-Bellinger-and-de-Veaux-and-Other-Families-by-Joseph-Gaston-Baillie-Bulloch.pdf
    • http://loaminoo.linkpc.net/7093096090098091/The-Escape-Artists-A-Band-of-Daredevil-Pilots-and-the-Greatest-Prison-Break-of-the-Great-War-by-Neal-Bascomb.pdf
    • http://loaminoo.linkpc.net/4093092094097092/The-Escape-Artists-A-Band-of-Daredevil-Pilots-and-the-Greatest-Prison-Break-of-the-Great-War-by-Neal-Bascomb.pdf
    • http://loaminoo.linkpc.net/4093092098093090/The-Quick-and-the-Dead-Fallen-Soldiers-and-Thei