Malicious PDF — malware analysis report

Static analysis result for SHA-256 3be38f45b9de0fc9…

MALICIOUS

PDF

21.1 KB Created: 2019-05-07 03:38:39 +01:00 Authoring application: mPDF 5.7
MD5: 019a5cda1eab801684300d79359132b9 SHA-1: 19ec97d4b6d8f57636ddb5f21bf715d0defbf3a1 SHA-256: 3be38f45b9de0fc9781aa476f0b7c2af317e249b01ee3bb5ec98a48ad531f946
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign-looking book titles, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, likely for SEO poisoning or to distribute further malware. The embedded URLs are the primary IOCs, and the attack pattern involves leveraging a link farm within a PDF document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5091091092095097/Ben-McCulloch-and-the-Frontier-Military-Tradition-by-Thomas-W-Cutrer.pdf
    • http://loaminoo.linkpc.net/4098090090091/The-Triumph-of-Tradition-by-G-Thomas-Edwards.pdf
    • http://loaminoo.linkpc.net/1095093097097/The-Essential-Tension-Selected-Studies-in-Scientific-Tradition-and-Change-by-Thomas-S-Kuhn.pdf
    • http://loaminoo.linkpc.net/5091099090097098/La-Frontera-Forests-and-Ecological-Conflict-in-Chile-s-Frontier-Territory-by-Thomas-Miller-Klubock.pdf
    • http://loaminoo.linkpc.net/1095099097098096/The-Military-Revolution-Military-Innovation-and-the-Rise-of-the-West-1500-1800-by-Geoffrey-Parker.pdf
    • http://loaminoo.linkpc.net/6091095099097092/Jarhead-Happy-Ending-Gay-Military-Massage-Erotic-Romance-Military-Masseur-by-Andrew-Mann.pdf
    • http://loaminoo.linkpc.net/1096092095098094/The-Accidental-Recluse-by-Tom-McCulloch.pdf
    • http://loaminoo.linkpc.net/1096098091090099/Final-Frontier-New-Frontier-2-by-Cliff-Ball.pdf
    • http://loaminoo.linkpc.net/1099090090098095/Barriers-To-Belief-Steps-To-A-Stronger-Faith-by-Nigel-McCulloch.pdf
    • http://loaminoo.linkpc.net/6090097096095099/The-Humanistic-Tradition-Prehistory-to-the-Early-Modern-World-The-Humanistic-Tradition-1-by-Gloria-K-Fiero.pdf
    • http://loaminoo.linkpc.net/5090099093092095/Defending-the-Indefensible-The-Global-Asbestos-Industry-and-Its-Fight-for-Survival-by-Jock-McCulloch.pdf
    • http://loaminoo.linkpc.net/8090094097099/A-Widow-s-Tale-The-1884-1896-Diary-of-Helen-Mar-Kimball-Whitney-Life-Writings-of-Frontier-Women-Vol-6-Life-Writings-of-Frontier-Women-by-Helen-Mar-Whitney.pdf
    • http://loaminoo.linkpc.net/9098095092095097/Tess-of-the-D-urbervilles-by-Thomas-Hardy-Illustrated-Delphi-Parts-Edition-Thomas-Hardy-by-Thomas-Hardy.pdf
    • http://loaminoo.linkpc.net/4092092099096096/Bonds-of-Tradition-by-J-M-Downey.pdf
    • http://loaminoo.linkpc.net/6096093094091097/The-Lanchester-Tradition-by-G-F-Bradby.pdf
    • http://loaminoo.linkpc.net/1097097096090092/Hostile-Military-Men-1-by-Leila-Haven.pdf
    • http://loaminoo.linkpc.net/1091090092090096090/The-Military-and-Modernization-by-Henry-Bienen.pdf
    • http://loaminoo.linkpc.net/2093092096098095/Kevin-My-Military-Man-by-Shane-Kaelle.pdf
    • http://loaminoo.linkpc.net/8093093090091095/The-Elf-off-the-Shelf-A-Christmas-Tradition-Gone-Bad-by-Horace-the-Elf.pdf
    • http://loaminoo.linkpc.net/9096098097097096/Gospel-According-to-John-in-the-Byzantine-Tradition-by-ABS.pdf
    • http://loaminoo.linkpc.net/6091095099097092/Jarhead-Happy-Ending-Gay-Military-Mass