Malicious PDF — malware analysis report

Static analysis result for SHA-256 374c6a7a8bf3983b…

MALICIOUS

PDF

14.6 KB Created: 2019-05-02 18:44:19 +01:00 Authoring application: mPDF 5.7
MD5: ac628b5f5d8b8ec2505ca20feac918d3 SHA-1: fe8b0bb6b488a5d1b86b6f406607c63fad7f9e25 SHA-256: 374c6a7a8bf3983be4b2a2fee56f5ca97ba7b3e39b93d173d198a1d6d63cd26e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. While the URLs themselves are currently flagged as benign, the sheer volume and structure suggest a malicious intent, likely for SEO poisoning or to redirect users to potentially harmful sites. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4098091094097093/Christmas-Every-Day-Those-Sinclairs-3-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/9092096098096090/The-Colton-Ransom-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/3097094093092094/Wife-in-the-Mail-The-Alaskans-1-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/7092093099094094/The-Setup-Hotel-Marchand-2-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/2091091097099099/Lassoing-the-Deputy-Forever-Texas-4-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/1092096091099/Mommy-and-the-Policeman-Next-Door-Tripopulous-1-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/2095096094091/Cowboy-for-Hire-Forever-Texas-11-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/2090092095096096/Her-Sworn-Protector-The-Doctors-Pulaski-3-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/3092096092099097/Colton-by-Marriage-The-Coltons-of-Montana-1-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/5090095096090095/Colton-Copycat-Killer-The-Coltons-of-Texas-1-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/3090096097090099/Secret-Agent-Affair-The-Doctors-Pulaski-5-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/2095092096098/A-Baby-on-the-Ranch-Ramona-and-the-Renegade-Forever-Texas-5-amp-2-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/2090092095094092/Cavanaugh-s-Woman-Cavanaugh-Justice-6-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/2090095093098/Cavanaugh-Reunion-Cavanaugh-Justice-19-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/6097092093091091/F-MININ-SINGULIER-by-L-a-Duffy.pdf
    • http://loaminoo.linkpc.net/8095092093093099/Le-Travail-Social-Au-Singulier-by-Jacques-Ion.pdf
    • http://loaminoo.linkpc.net/6098094099093099/Warfighting-Marine-Corps-Doctrinal-Publication-1-by-U-S-Marine-Corps.pdf
    • http://loaminoo.linkpc.net/5099098091091091/The-Theory-of-the-Avant-Garde-by-Renato-Poggioli.pdf
    • http://loaminoo.linkpc.net/1093093099090099/Twice-a-Prince-Sasharia-en-Garde-2-by-Sherwood-Smith.pdf
    • http://loaminoo.linkpc.net/4096090093096098/Twice-a-Prince-Sasharia-en-Garde-2-by-Sherwood-Smith.pdf
    • http://loaminoo.linkpc.net/20950