Malicious PDF — malware analysis report

Static analysis result for SHA-256 43de30db6318f3c9…

MALICIOUS

PDF

19.5 KB Created: 2019-04-30 03:35:50 +01:00 Authoring application: mPDF 5.7
MD5: 3865b4382e72a70a1b4e27da7bfd2036 SHA-1: 0398f90b9c9632fa85319ab1d37dd05065a8db6f SHA-256: 43de30db6318f3c9dfa1972f05bd5d88aa355aaa4dc87091cbad14646ca3f2ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier with high confidence and contains a large number of embedded external links. The heuristic PDF_SEO_LINK_FARM indicates a link farm, suggesting these links are intended to lead users to potentially malicious websites or phishing content. The document body is heavily obfuscated, preventing a clear understanding of its specific lure, but the link farm strongly suggests a malicious intent to redirect the user. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5091093093090/Illuminated-White-Road-Chronicles-1-by-Jackie-Castle.pdf
    • http://loaminoo.linkpc.net/5099099096094/Emanate-White-Road-Chronicles-3-by-Jackie-Castle.pdf
    • http://loaminoo.linkpc.net/4093095096094099/Castle-Darkest-Night-by-Joe-Vadalma.pdf
    • http://loaminoo.linkpc.net/5095096098093/6-weeks-of-white-castle-n-rust-by-Brandon-Thomas-DiSabatino.pdf
    • http://loaminoo.linkpc.net/8097091096096/Akiko-in-the-Castle-of-Alia-Rellapor-by-Mark-Crilley.pdf
    • http://loaminoo.linkpc.net/3095096099097097/Saturday-Night-Live-The-Book-by-Alison-Castle.pdf
    • http://loaminoo.linkpc.net/5090099094099097/Haunted-Hamilton-The-Ghosts-of-Dundurn-Castle-and-Other-Steeltown-Shivers-by-Mark-Leslie.pdf
    • http://loaminoo.linkpc.net/1093099091099090/The-Spanish-Labyrinth-An-Account-of-the-Social-and-Political-Background-of-the-Spanish-Civil-War-by-Gerald-Brenan.pdf
    • http://loaminoo.linkpc.net/1090096098090099093/English-Grammar-for-Students-of-Spanish-The-Study-Guide-for-Those-Learning-Spanish-by-Emily-Spinelli.pdf
    • http://loaminoo.linkpc.net/2094091092096/Spanish-Fever-Stories-by-the-New-Spanish-Cartoonists-by-Santiago-Garc-a.pdf
    • http://loaminoo.linkpc.net/4095092096091093/Trail-of-the-Spanish-Bit-Spanish-Bit-Saga-1-by-Don-Coldsmith.pdf
    • http://loaminoo.linkpc.net/1090095094096099097/Return-of-the-Spanish-Spanish-Bit-Saga-18-by-Don-Coldsmith.pdf
    • http://loaminoo.linkpc.net/3092095091090092/White-Man-s-God-by-Mark-Miller.pdf
    • http://loaminoo.linkpc.net/1091091096099091/White-Lies-by-Mark-O-39-Sullivan.pdf
    • http://loaminoo.linkpc.net/7093091097097/White-City-by-Mark-Irwin.pdf
    • http://loaminoo.linkpc.net/1090098093097099099/Accelerated-Spanish-Learn-fluent-Spanish-with-a-proven-accelerated-learning-system-by-Timothy-Moser.pdf
    • http://loaminoo.linkpc.net/9091091099097095/Danny-Duck-Tames-the-Lion-Danny-Pato-doma-al-Le-n---Bilingual-Book-in-English-and-Spanish-Study-Spanish-for-Kids-1-by-Colin-Hann.pdf
    • http://loaminoo.linkpc.net/3090098090094093/Batman-Black-and-White-Vol-3-by-Mark-Chiarello.pdf
    • http://loaminoo.linkpc.net/2093099091090/Batman-Black-and-White-Vol-2-by-Mark-Chiarello.pdf
    • http://loaminoo.linkpc.net/6096092099092090/Practical-Dictionary-of-Latin-American-Proverbs-with-Spanish-French-Quebec-French-and-English-Parallels-600-proverbial-sayings-of-Spanish-speaking-America-by-Pierre-DesRuisseaux.pdf
    • http://loaminoo.linkpc.net/1090096098090