Malicious PDF — malware analysis report

Static analysis result for SHA-256 42f9f1b1bdd5cde1…

MALICIOUS

PDF

17.9 KB Created: 2019-05-02 00:44:37 +01:00 Authoring application: mPDF 5.7
MD5: ceb080ce79e99a77921070bb800eeea5 SHA-1: e84b3cefa3a2b05460e761fb538bbc22fbdb2e58 SHA-256: 42f9f1b1bdd5cde1749ea4edaeea96e08b034216d59d798162d844af277a54ea
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness, and the PDF structure itself suggests a link farm. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the immediate user-facing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6094093091091090/Letters-for-Scarlet-Friendship-amp-Secrets-1-by-Julie-C-Gardner.pdf
    • http://loaminoo.linkpc.net/2098093095091093/Scarlet-Secrets-Book-Two-in-the-Scarlet-Series-by-Lani-Wendt-Young.pdf
    • http://loaminoo.linkpc.net/3097091096098096/Friendship-Over-by-Julie-Sternberg.pdf
    • http://loaminoo.linkpc.net/5099096099097/Two-Eggs-Two-Kids-An-Egg-Donor-s-Account-of-Friendship-Infertility-amp-Secrets-by-Alicia-Young.pdf
    • http://loaminoo.linkpc.net/8097091095099098/Antonia-and-Her-Daughters-Secrets-Love-Friendship-and-Family-in-Tuscany-by-Marlena-de-Blasi.pdf
    • http://loaminoo.linkpc.net/1091093096099091092/Dorothy-Thompson-and-Rose-Wilder-Lane-Forty-Years-of-Friendship-Letters-1921-1960-by-William-Holtz.pdf
    • http://loaminoo.linkpc.net/3099098098091090/Secrets-of-Bella-Terra-Scarlet-Deception-1-by-Christina-Dodd.pdf
    • http://loaminoo.linkpc.net/1091096099096/Secrets-of-Bella-Terra-Scarlet-Deception-1-by-Christina-Dodd.pdf
    • http://loaminoo.linkpc.net/3094098093094093/Ripple-of-Secrets-Rose-Gardner-Mystery-6-5-by-Denise-Grover-Swank.pdf
    • http://loaminoo.linkpc.net/1090094095095094098/Animals-amp-Letters-An-ABC-Book-for-Children-Learning-the-Alphabet-by-Julie-Sonnen.pdf
    • http://loaminoo.linkpc.net/6099093095099/Deny-Friendship-Darkly-Fun-Mystery-The-Frank-Friendship-Series-Book-3-by-R-G-Manse.pdf
    • http://loaminoo.linkpc.net/1099097090094097/57-Secrets-for-Organizing-Your-Small-Business-by-Julie-Bestry.pdf
    • http://loaminoo.linkpc.net/6095094091094095/Pen-in-the-Dark-Narratives-letters-secrets-and-poems-by-Douze.pdf
    • http://loaminoo.linkpc.net/4092091090092092/Secrets-Letters-and-Lies-Celia-s-Journey-Book-4-by-Melissa-Gunther.pdf
    • http://loaminoo.linkpc.net/1090090090097090096/A-Late-Friendship-The-Letters-of-Karl-Barth-and-Carl-Zuckmayer-by-Carl-Zuckmayer.pdf
    • http://loaminoo.linkpc.net/3099090095094093/Scarlet-and-the-Keepers-of-Light-Scarlet-Hopewell-1-by-Brandon-Charles-West.pdf
    • http://loaminoo.linkpc.net/6094093090096091/Scarlet-Book-2-Scarlet-2-by-Brian-Michael-Bendis.pdf
    • http://loaminoo.linkpc.net/1099093090099095/Scarlet-Book-1-Scarlet-1-by-Brian-Michael-Bendis.pdf
    • http://loaminoo.linkpc.net/5099099090092099/Scarlet-Widow-Beatrice-Scarlet-1-by-Graham-Masterton.pdf
    • http://loaminoo.linkpc.net/1091093091093099094/Gardner-s-Art-Through-the-Ages-Vol-1-Chapters-1-18-by-Helen-Gardner.pdf