Malicious PDF — malware analysis report

Static analysis result for SHA-256 33d48091693af341…

MALICIOUS

PDF

20.7 KB Created: 2019-04-30 04:34:58 +01:00 Authoring application: mPDF 5.7
MD5: 2bb39990847d6bce7cb9d1b08f45a938 SHA-1: 650c3de026eb1b4ef2d85f75d824bd6d1f66728e SHA-256: 33d48091693af341d246d47e3ca5a55b996a399c80b4ea6b093c1e690f91b360
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. While the document body is unreadable, the structure and the presence of numerous external links suggest a malicious intent, possibly for SEO manipulation or to distribute malware. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7098093095098092/History-as-They-Lived-It-A-Social-History-of-Prairie-Du-Rocher-Illinois-by-Margaret-Kimball-Brown.pdf
    • http://loaminoo.linkpc.net/4098096099096098/World-History-Ancient-History-United-States-History-European-Native-American-Russian-Chinese-Asian-Indian-and-Australian-History-Wars-including-World-War-1-and-2-by-Adam-Brown.pdf
    • http://loaminoo.linkpc.net/6097096093096098/Women-s-History-History-of-the-Prairie-West-5-by-Gregory-P-Marchildon.pdf
    • http://loaminoo.linkpc.net/6098092092096098/THE-BEST-HISTORY-4-in-1-HISTORY-OF-ASIA-HISTORY-OF-chaina-HISTORY-OF-COMMUNISM-HISTORY-OF-ENGLAND-by-Good-thailand.pdf
    • http://loaminoo.linkpc.net/6091098097093097/An-Unofficial-History-of-Mahomet-Illinois-by-Mayhaven-Publishing.pdf
    • http://loaminoo.linkpc.net/4098097098099090/Nibelungenlied-History-and-Interpretation-Illinois-Medieval-Monographs-by-Edward-W-Haymes.pdf
    • http://loaminoo.linkpc.net/1092091095097090/I-Have-Lived-Here-Since-the-World-Began-An-Illustrated-History-of-Canada-s-Native-People-by-Arthur-J-Ray.pdf
    • http://loaminoo.linkpc.net/4094097096098095/Poison-A-Social-History-by-Joel-Levy.pdf
    • http://loaminoo.linkpc.net/4094097094097095/Drive-On-A-Social-History-of-the-Motor-Car-by-L-J-K-Setright.pdf
    • http://loaminoo.linkpc.net/4094096093094093/The-Porcelain-God-A-Social-History-of-the-Toilet-by-L-Julie-Horn.pdf
    • http://loaminoo.linkpc.net/2092093097092098/In-The-Shadow-Of-Polio-A-Personal-And-Social-History-by-Kathryn-Black.pdf
    • http://loaminoo.linkpc.net/4093098090095090/Modern-Africa-A-Social-and-Political-History-by-Basil-Davidson.pdf
    • http://loaminoo.linkpc.net/3094093098091095/What-Is-Marriage-For-The-Strange-Social-History-of-Our-Most-Intimate-Institution-by-E-J-Graff.pdf
    • http://loaminoo.linkpc.net/2090090094090093/Mathematics-in-Ancient-Iraq-A-Social-History-by-Eleanor-Robson.pdf
    • http://loaminoo.linkpc.net/4094096098092097/The-Smoke-of-the-Gods-A-Social-History-of-Tobacco-by-Eric-Burns.pdf
    • http://loaminoo.linkpc.net/4094097093094098/Artificial-Sunshine-A-Social-History-of-Lighting-by-Maureen-Dillon.pdf
    • http://loaminoo.linkpc.net/8096094098093093/Wasteland-with-Words-A-Social-History-of-Iceland-by-Sigurdur-Gylfi-Magnusson.pdf
    • http://loaminoo.linkpc.net/5091090092097090/The-Real-Deal-The-History-and-Future-of-Social-Security-by-Sylvester-J-Schieber.pdf
    • http://loaminoo.linkpc.net/3093099092092092/The-Hidden-Lives-of-Tudor-Women-A-Social-History-by-Elizabeth-Norton.pdf
    • http://loaminoo.linkpc.net/1093096094094096/Northern-Sandlots-A-Social-History-of-Maritime-Baseball-by-Colin-D-Howell.pdf