Malicious PDF — malware analysis report

Static analysis result for SHA-256 3aabf9d62eba8766…

MALICIOUS

PDF

14.1 KB Created: 2019-04-30 04:48:06 +01:00 Authoring application: mPDF 5.7
MD5: 085ea1cc3356a33e2270e302e954bc8c SHA-1: 7b702d6f6ea66de9d4ce6f31550feaec89f3a70e SHA-256: 3aabf9d62eba876690d7182da390f392c100b81caac416da5578d06632f2815f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to book titles and are marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to manipulate search engine results or redirect users to harmful sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/8096091097093/13-Secrets-Thirteen-Treasures-3-by-Michelle-Harrison.pdf
    • http://loaminoo.linkpc.net/3098090096090096/One-Wish-Thirteen-Treasures-0-5-by-Michelle-Harrison.pdf
    • http://loaminoo.linkpc.net/4090098095095/Thirteen-by-Scott-Harrison.pdf
    • http://loaminoo.linkpc.net/2099094091090096/First-Response-Tombstone-Treasures-3-by-Michelle-Sutton.pdf
    • http://loaminoo.linkpc.net/8099099099091/Tell-Me-the-Secrets-Treasures-for-Eternity-by-Max-Lucado.pdf
    • http://loaminoo.linkpc.net/3090095092097097/Treasures-Lost-Treasures-Found-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/3099095091095098/Uncovering-Her-Secrets-Seals-Security-2-by-Michelle-Woods.pdf
    • http://loaminoo.linkpc.net/3090092093096096/Undressed-by-the-Earl-Secrets-in-Silk-3-by-Michelle-Willingham.pdf
    • http://loaminoo.linkpc.net/2095097090094/Secrets-To-Seducing-A-Scot-Highland-Knaves-1-by-Michelle-Marcos.pdf
    • http://loaminoo.linkpc.net/4091096090096096/Keeper-of-the-King-s-Secrets-Susanna-Horenbout-and-John-Parker-2-by-Michelle-Diener.pdf
    • http://loaminoo.linkpc.net/5099096091090/Secrets-of-Power-Negotiating-Inside-Secrets-from-a-Master-Negotiator-by-Roger-Dawson.pdf
    • http://loaminoo.linkpc.net/4092098097091090/Michelle-Obama-Speeches-on-Life-Love-and-American-Values-by-Michelle-Obama.pdf
    • http://loaminoo.linkpc.net/9095099098098/Thirteen-by-Richard-K-Morgan.pdf
    • http://loaminoo.linkpc.net/1093098098093096/These-Thirteen-by-William-Faulkner.pdf
    • http://loaminoo.linkpc.net/4090091097096093/Thirteen-by-Shannon-L-Peel.pdf
    • http://loaminoo.linkpc.net/1091092092090094/Thirteen-Reasons-Why-by-Jay-Asher.pdf
    • http://loaminoo.linkpc.net/1098098096/Thirteen-Ways-of-Looking-by-Colum-McCann.pdf
    • http://loaminoo.linkpc.net/3094099095095090/Thirteen-Ways-of-Looking-by-Colum-McCann.pdf
    • http://loaminoo.linkpc.net/1091094091090093091/Bean-Thirteen-by-Matthew-McElligott.pdf
    • http://loaminoo.linkpc.net/4090099093090095/Thirteen-At-Dinner-by-Agatha-Christie.pdf