Malicious PDF — malware analysis report

Static analysis result for SHA-256 37013f9b9422c4c1…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 09:54:17 +01:00 Authoring application: mPDF 5.7
MD5: 0dc8c1b2de90f1b62961464efa18ad74 SHA-1: 0fddf85c6fc4d5e7ed15af528bc6fa00172d2398 SHA-256: 37013f9b9422c4c14f80c816b0b7ca433c7949bcfc04cbdd57445f6d92336177
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a potential for malicious redirection or content hosting. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1095097090098091/Mr-Fox-by-Helen-Oyeyemi.pdf
    • http://loaminoo.linkpc.net/2091096091092094/Mr-Fox-by-Helen-Oyeyemi.pdf
    • http://loaminoo.linkpc.net/5093098097090/White-is-for-Witching-by-Helen-Oyeyemi.pdf
    • http://loaminoo.linkpc.net/2094098096095095/Boy-Snow-Bird-by-Helen-Oyeyemi.pdf
    • http://loaminoo.linkpc.net/9091098097097/The-Opposite-House-by-Helen-Oyeyemi.pdf
    • http://loaminoo.linkpc.net/5094097096095091/Enter-Helen-The-Invention-of-Helen-Gurley-Brown-and-the-Rise-of-the-Modern-Single-Woman-by-Brooke-Hauser.pdf
    • http://loaminoo.linkpc.net/3095094095099098/The-Good-Life-Helen-and-Scott-Nearing-s-Sixty-Years-of-Self-Sufficient-Living-by-Helen-Nearing.pdf
    • http://loaminoo.linkpc.net/2095095093094098/Lady-Helen-and-the-Dark-Days-Club-Lady-Helen-1-by-Alison-Goodman.pdf
    • http://loaminoo.linkpc.net/3099095090094098/Answer-Me-This-by-Helen-Zaltzman-Olly-Mann-by-Helen-Zaltzman.pdf
    • http://loaminoo.linkpc.net/6090093093098092/To-Love-This-Life-Quotations-By-Helen-Keller-by-Helen-Keller.pdf
    • http://loaminoo.linkpc.net/8090094097099/A-Widow-s-Tale-The-1884-1896-Diary-of-Helen-Mar-Kimball-Whitney-Life-Writings-of-Frontier-Women-Vol-6-Life-Writings-of-Frontier-Women-by-Helen-Mar-Whitney.pdf
    • http://loaminoo.linkpc.net/3091090097098/Mad-About-the-Boy-by-Helen-Fielding.pdf
    • http://loaminoo.linkpc.net/1090091093093090/Helen-by-Euripides.pdf
    • http://loaminoo.linkpc.net/4099095099091092/Our-Dog-by-Helen-Oxenbury.pdf
    • http://loaminoo.linkpc.net/1091097098099/From-the-Outside-by-Helen-Brenna.pdf
    • http://loaminoo.linkpc.net/8094099091097097/Mad-about-the-boy-by-Helen-Fielding.pdf
    • http://loaminoo.linkpc.net/2090099091093097/More-Than-You-Know-by-Helen-R-Myers.pdf
    • http://loaminoo.linkpc.net/1091091090091091090/Ever-This-Day-by-Helen-Moorhouse.pdf
    • http://loaminoo.linkpc.net/1099097097092099/Cause-Celeb-by-Helen-Fielding.pdf
    • http://loaminoo.linkpc.net/2099094097090095/Everything-Is-Lies-by-Helen-Callaghan.pdf
    • http://loaminoo.linkpc.net/3095094095099098/The-Good-Life-Helen-and-Scott-Nearing-s-Sixty-Yea