Malicious PDF — malware analysis report

Static analysis result for SHA-256 443bab0b653413ee…

MALICIOUS

PDF

14.6 KB Created: 2019-05-07 02:50:57 +01:00 Authoring application: mPDF 5.7
MD5: a89a76aace4a5c7b057716ebb21b8221 SHA-1: 560090c1c664b4b0ec7da4eec30cd162dbb00606 SHA-256: 443bab0b653413eebe97be4e7b99dbbe0df042d1ce468127ff170977f693c877
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as confirmed benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to distribute further malware. No scripts were extracted from this sample. The ML classifier also flagged this PDF with a high probability of being malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093099092093/Scary-Godmother-The-Boo-Flu-by-Jill-Thompson.pdf
    • http://loaminoo.linkpc.net/2099098090090099/Scary-Godmother-Omnibus-by-Jill-Thompson.pdf
    • http://loaminoo.linkpc.net/2099092090099092/Scary-Godmother-Wild-About-Harry-by-Jill-Thompson.pdf
    • http://loaminoo.linkpc.net/3097093098095099/Scary-Godmother-Comic-Book-Stories-by-Jill-Thompson.pdf
    • http://loaminoo.linkpc.net/2094092092096092/The-Little-Endless-Storybook-by-Jill-Thompson.pdf
    • http://loaminoo.linkpc.net/4099092097096/Scary-No-Scary-by-Zachary-Schomburg.pdf
    • http://loaminoo.linkpc.net/1090097099097093094/The-Lost-King-of-Oz-Oz-Thompson-and-others-19-by-Ruth-Plumly-Thompson.pdf
    • http://loaminoo.linkpc.net/2094094091097099/Jill-s-Pony-Trek-Jill-s-Ponies-9-by-Ruby-Ferguson.pdf
    • http://loaminoo.linkpc.net/2094094091097092/Jill-s-Riding-Club-Jill-s-Ponies-5-by-Ruby-Ferguson.pdf
    • http://loaminoo.linkpc.net/2096097098095097/The-Way-of-The-Fairy-Godmother-by-Jennifer-Morse.pdf
    • http://loaminoo.linkpc.net/3098090095098097/The-Magic-Mistake-Oh-My-Godmother-2-by-Barbara-Brauner.pdf
    • http://loaminoo.linkpc.net/9092090093096099/The-Downtown-Fairy-Godmother-by-Charlotte-Pomerantz.pdf
    • http://loaminoo.linkpc.net/2098098090099090/The-World-s-Worst-Fairy-Godmother-by-Bruce-Coville.pdf
    • http://loaminoo.linkpc.net/2093093095093093/Catspell-The-Fairy-Godmother-Dilemma-1-by-Danyelle-Leafty.pdf
    • http://loaminoo.linkpc.net/1090095091095096/Godmother-The-Secret-Cinderella-Story-by-Carolyn-Turgeon.pdf
    • http://loaminoo.linkpc.net/8093099091095/Personally-I-Blame-My-Fairy-Godmother-by-Claudia-Carroll.pdf
    • http://loaminoo.linkpc.net/3096092092091/The-Fairy-Godmother-Five-Hundred-Kingdoms-1-by-Mercedes-Lackey.pdf
    • http://loaminoo.linkpc.net/2097099098096098/Zally-s-Book-The-Fairy-Godmother-Academy-3-by-Jan-Bozarth.pdf
    • http://loaminoo.linkpc.net/8093092090095099/Jill-Prescott-s-Ecole-De-Cuisine-Professional-Cooking-for-the-Home-Chef-by-Jill-Prescott.pdf
    • http://loaminoo.linkpc.net/2091090099096098/The-Writings-of-David-Thompson-Volume-1-The-Travels-1850-Version-by-David-Thompson.pdf
    • http://loaminoo.linkpc.net/2098098090099090/The-World-s-Worst-Fairy-Godmother-by-Bruce-Coville.pd