Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e924b3d26845a38…

MALICIOUS

PDF

16.6 KB Created: 2019-04-30 03:39:44 +01:00 Authoring application: mPDF 5.7
MD5: ae551ac8beef139bc933f4bd60895c08 SHA-1: 5a21b7fc2d5afdf7bd25de649f0ae630ace9ebde SHA-256: 3e924b3d26845a3875a59dc417cb760243ae439e0ed97b087ffc3f4e98ffd27f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to distribute further malware. The ML_NYX_PDF_MALICIOUS classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097098092099091/Frontier-City-Toronto-on-the-Verge-of-Greatness-by-Shawn-Micallef.pdf
    • http://loaminoo.linkpc.net/7095097091094091/Stroll-Psychogeographic-Walking-Tours-of-Toronto-by-Shawn-Micallef.pdf
    • http://loaminoo.linkpc.net/7095097091091093/Toronto-Biography-of-a-City-by-Allan-Levine.pdf
    • http://loaminoo.linkpc.net/7095097091094099/Toronto-and-the-Maple-Leafs-A-City-and-Its-Team-by-Lance-Hornby.pdf
    • http://loaminoo.linkpc.net/1090091090095097097/City-Voices-A-Book-of-Monologues-by-Toronto-Artists-by-Jenna-Harris.pdf
    • http://loaminoo.linkpc.net/7095097092095098/The-Toronto-Carrying-Place-Rediscovering-Toronto-s-Most-Ancient-Trail-by-Glenn-Turner.pdf
    • http://loaminoo.linkpc.net/5094090096095099/Edge-City-Life-on-the-New-Frontier-by-Joel-Garreau.pdf
    • http://loaminoo.linkpc.net/7095097091094098/Toronto-Comics-Yonge-at-Heart-Toronto-Comics-4-by-Steven-Andrews.pdf
    • http://loaminoo.linkpc.net/3097096090091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/4098093094096091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/1096098091090099/Final-Frontier-New-Frontier-2-by-Cliff-Ball.pdf
    • http://loaminoo.linkpc.net/3097097095097094/Verge-by-Z-Egloff.pdf
    • http://loaminoo.linkpc.net/4092094095091092/On-The-Verge-by-Ariella-Papa.pdf
    • http://loaminoo.linkpc.net/2096098091092092/On-the-Verge-by-Garen-Glazier.pdf
    • http://loaminoo.linkpc.net/2091099092093090/Girl-on-the-Verge-by-Pintip-Dunn.pdf
    • http://loaminoo.linkpc.net/4091092094096099/Girls-on-the-Verge-by-Sharon-Biggs-Waller.pdf
    • http://loaminoo.linkpc.net/1098098099090093/Love-on-the-Ledge-On-the-Verge-2-by-Zoraida-C-rdova.pdf
    • http://loaminoo.linkpc.net/6091097090091097/Fairytale-Apocalypse-The-Verge-1-by-Jacqueline-Patricks.pdf
    • http://loaminoo.linkpc.net/4093099092098094/On-The-Verge-Or-The-Geography-Of-Yearning-by-Eric-Overmyer.pdf
    • http://loaminoo.linkpc.net/1090098096090093095/On-the-Verge-of-I-Do-Dynasties-The-Kincaids-4-by-Heidi-Betts.pdf