Malicious PDF — malware analysis report

Static analysis result for SHA-256 3800cb205ec9d28f…

MALICIOUS

PDF

18.0 KB Created: 2019-05-03 15:11:15 +01:00 Authoring application: mPDF 5.7
MD5: c80089869d9beb5bfb861dbd9f23d093 SHA-1: 40a1233846a71a65e9e2337ab49c943141b59a5b SHA-256: 3800cb205ec9d28f426628979180c81fd0ae6a740f77a7d1ae64f06a49d055b5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was heavily corrupted, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5095099097095/The-Collected-Poems-of-F-R-Scott-by-F-R-Scott.pdf
    • http://loaminoo.linkpc.net/1091098099099090098/Flappers-and-Philosophers-1920-by-Francis-Scott-Fitzgerald-Francis-Scott-Key-Fitzgerald-September-24-1896---December-21-1940-Known-Professionally-as-F-Scott-Fitzgerald-Was-an-American-Novelist-and-Short-Story-Writer-Whose-Works-Illustrate-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/3094094099091097/I-Dred-Scott-A-Fictional-Slave-Narrative-Based-on-the-Life-and-Legal-Precedent-of-Dred-Scott-by-Shelia-P-Moses.pdf
    • http://loaminoo.linkpc.net/1099091091099095/The-Complete-Works-of-F-Scott-Fitzgerald-Classics-Book-8-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/4090099092090/Scott-Pilgrim-Volume-2-Scott-Pilgrim-vs-The-World-by-Bryan-Lee-O-39-Malley.pdf
    • http://loaminoo.linkpc.net/4096090098091096/Scott-Pilgrim-Volume-2-Scott-Pilgrim-vs-The-World-by-Bryan-Lee-O-39-Malley.pdf
    • http://loaminoo.linkpc.net/4098094096091/Poems-from-Ish-River-Country-Collected-Poems-and-Translations-by-Robert-Sund.pdf
    • http://loaminoo.linkpc.net/8092092090096099/Lady-of-the-Lake-Walter-Scott-1910-by-Walter-Scott.pdf
    • http://loaminoo.linkpc.net/1099092095095090/F-Scott-Fitzgerald-Tales-of-the-Jazz-Age-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/8091096098094095/Works-of-F-Scott-Fitzgerald-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/8095092098092096/The-Collected-Poems-by-A-E-Housman.pdf
    • http://loaminoo.linkpc.net/4095099098098092/New-Collected-Poems-by-Les-Murray.pdf
    • http://loaminoo.linkpc.net/5090096099098092/Collected-Poems-by-Primo-Levi.pdf
    • http://loaminoo.linkpc.net/5098094091090094/The-Collected-Poems-by-Muriel-Rukeyser.pdf
    • http://loaminoo.linkpc.net/3091092090098/Collected-Poems-by-Mark-Strand.pdf
    • http://loaminoo.linkpc.net/3093092092099093/Collected-Poems-by-Patrick-Kavanagh.pdf
    • http://loaminoo.linkpc.net/2093096093097/Collected-Poems-by-Josephine-Miles.pdf
    • http://loaminoo.linkpc.net/9095098093093096/Collected-Poems-by-Patricia-Dobler.pdf
    • http://loaminoo.linkpc.net/8090096091093/Collected-Poems-by-Patrick-Kavanagh.pdf
    • http://loaminoo.linkpc.net/2093091092098/The-Collected-Poems-by-Howard-Nemerov.pdf
    • http://loaminoo.linkpc.net/4098094096091/Poems-from-Ish-River-Country-Collected-Poem