Malicious PDF — malware analysis report

Static analysis result for SHA-256 41cc730fa7fb8d04…

MALICIOUS

PDF

17.4 KB Created: 2019-04-30 05:26:38 +01:00 Authoring application: mPDF 5.7
MD5: c990f7245a184f1ad82488c7e7c6edf7 SHA-1: 3888b7d82bf8629bef3ed8b498ec247528d91dae SHA-256: 41cc730fa7fb8d04411fe3a53ae4716c6e1df6bd9ff5b62eec2dadd2a61f12a9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a link farm or redirection scheme. While the specific URLs extracted were marked as benign, the sheer volume and structure indicate a malicious intent, likely to manipulate search engine results or redirect users to malicious sites. The ML_NYX_PDF_MALICIOUS classifier also flagged this sample with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1092090093093093/My-Enemy-s-Tears-The-Witch-of-Northampton-by-Karen-Vorbeck-Williams.pdf
    • http://loaminoo.linkpc.net/4092095092093095/The-Enemy-of-an-Enemy-Lost-Tales-of-Power-1-by-Vincent-Trigili.pdf
    • http://loaminoo.linkpc.net/3093094093094095/Enemy-of-My-Enemy-Terra-Nova-1-by-Ben-Ohlander.pdf
    • http://loaminoo.linkpc.net/3090099099097090/Enemy-Outside-Unseen-Enemy-2-by-Marysol-James.pdf
    • http://loaminoo.linkpc.net/7097097097093091/Rise-of-the-Enemy-The-Enemy-2-by-Rob-Sinclair.pdf
    • http://loaminoo.linkpc.net/2096096091097096/Enemy-Within-Enemy-1-by-Marcella-Burnard.pdf
    • http://loaminoo.linkpc.net/1091099095097091/Dance-with-the-Enemy-The-Enemy-1-by-Rob-Sinclair.pdf
    • http://loaminoo.linkpc.net/4092091098094/The-Enemy-The-Enemy-1-by-Charlie-Higson.pdf
    • http://loaminoo.linkpc.net/3097099090090097/The-Enemy-The-Enemy-1-by-Charlie-Higson.pdf
    • http://loaminoo.linkpc.net/7097097096098091/Dance-with-the-Enemy-The-Enemy-1-by-Rob-Sinclair.pdf
    • http://loaminoo.linkpc.net/3090099097092098/Cooking-at-Home-Williams-Sonoma-by-Chuck-Williams.pdf
    • http://loaminoo.linkpc.net/6091098099099094/Savoring-Provence-Recipes-And-Reflections-On-Proven-al-Cooking-Williams-Sonoma-Savoring-Series-by-Chuck-Williams.pdf
    • http://loaminoo.linkpc.net/4091097099099090/The-Complete-Writings-of-Roger-Williams---Volume-3-Bloudy-Tenent-of-Persecution-by-Roger-Williams.pdf
    • http://loaminoo.linkpc.net/1091098093098095097/-The-Exiled-Queen-The-Seven-Realms-Series-Book-2-By-Cinda-Williams-Chima-published-November-2011-by-Cinda-Williams-Chima.pdf
    • http://loaminoo.linkpc.net/6095098099093090/Selected-Poems-of-William-Carlos-Williams-New-Directions-Paperbook-by-William-Carlos-Williams.pdf
    • http://loaminoo.linkpc.net/1097098098094094/The-Enemy-Within-by-Lynette-White.pdf
    • http://loaminoo.linkpc.net/1096098099099/Enemy-Combatant-by-Ed-Gaffney.pdf
    • http://loaminoo.linkpc.net/2094098096099091/In-the-Arms-of-the-Enemy-by-Lisbeth-Eng.pdf
    • http://loaminoo.linkpc.net/2093099099090092/Enemy-Among-Us-by-Kevin-Hamilton.pdf
    • http://loaminoo.linkpc.net/4092098093094090/The-Enemy-Within-by-Connor-Fitzgerald.pdf