Malicious PDF — malware analysis report

Static analysis result for SHA-256 456f0bb4849ddd36…

MALICIOUS

PDF

16.2 KB Created: 2019-05-07 03:59:39 +01:00 Authoring application: mPDF 5.7
MD5: 158c8df8ec2ca0ad20cf10c79e6fd234 SHA-1: 4cf9136b8e8c8faae06fe33a77b3a6a56d948b83 SHA-256: 456f0bb4849ddd36a104f3975ef84119d07b96459212b014e6448d7e215161dc
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external websites, identified as a link farm. While the document body is heavily obfuscated, the heuristic 'PDF_SEO_LINK_FARM' indicates a malicious intent to direct users to numerous external resources. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8096099090094/The-Rose-Chateau-A-Tale-of-Beauty-Meets-Beast-by-Rebecca-Monaco.pdf
    • http://loaminoo.linkpc.net/5096099093095093/Beauty-and-the-Beast-Not-Quite-the-Fairy-Tale-3-by-May-Sage.pdf
    • http://loaminoo.linkpc.net/2096094090096099/Beauty-and-the-Beast-Not-Quite-the-Fairy-Tale-3-by-May-Sage.pdf
    • http://loaminoo.linkpc.net/1097098094094098/Beauty-of-the-Beast-Fairy-Tale-Retellings-1-by-Rachel-L-Demeter.pdf
    • http://loaminoo.linkpc.net/4093091094095096/Rose-and-the-Monster-A-Modern-Retelling-of-Beauty-and-the-Beast-by-M-Lowry.pdf
    • http://loaminoo.linkpc.net/2093092090094098/Beauty-Beast-and-Belladonna-Fairy-Tale-Fatal-Mystery-3-by-Maia-Chance.pdf
    • http://loaminoo.linkpc.net/2090094091092098/Isabelle-and-the-Beast-A-Retelling-of-Beauty-and-the-Beast-by-Dee-J-Stone.pdf
    • http://loaminoo.linkpc.net/4094090094096092/Beauty-and-Beastly-Steampunk-Fairy-Tales-Beauty-and-the-Beast-1-by-Melanie-Karsak.pdf
    • http://loaminoo.linkpc.net/8097097091090/Beauty-A-Retelling-of-the-Story-of-Beauty-and-the-Beast-by-Robin-McKinley.pdf
    • http://loaminoo.linkpc.net/1094091099099/Beauty-A-Retelling-of-the-Story-of-Beauty-and-the-Beast-by-Robin-McKinley.pdf
    • http://loaminoo.linkpc.net/2090090095094095/Beauty-Touched-the-Beast-Beauty-1-by-Skye-Warren.pdf
    • http://loaminoo.linkpc.net/3097090097099094/Hunted-An-Erotic-Retelling-of-Beauty-and-the-Beast-Hunted-by-the-Beast-1-5-by-Cerys-du-Lys.pdf
    • http://loaminoo.linkpc.net/2098095091095098/Christian-Lacroix-and-the-Tale-of-Sleeping-Beauty-A-Fashion-Fairy-Tale-Memoir-by-Camilla-Morton.pdf
    • http://loaminoo.linkpc.net/2098095095096095/The-Beauty-s-Beast-by-E-D-Walker.pdf
    • http://loaminoo.linkpc.net/2097096093092099/The-Beauty-of-a-Beast-by-starofjems.pdf
    • http://loaminoo.linkpc.net/2090092098097090/Beauty-and-the-Beast-by-Marianna-Mayer.pdf
    • http://loaminoo.linkpc.net/4093091094093090/Masques-Beauty-and-the-Beast-2-by-Ru-Emerson.pdf
    • http://loaminoo.linkpc.net/3098093094095/Beauty-and-the-Beast-by-Jennifer-Donnelly.pdf
    • http://loaminoo.linkpc.net/1099099097097096/Beauty-and-the-Beast-by-Teddy-Slater.pdf
    • http://loaminoo.linkpc.net/8092097098099/Beauty-and-the-Beast-by-Charles-Perrault.pdf
    • http://loaminoo.linkpc.net/2090090095094095/Beauty-Touched-the-Beast-Beauty-1-by-Skye-Warre