Malicious PDF — malware analysis report

Static analysis result for SHA-256 49516a5af31dc24c…

MALICIOUS

PDF

18.2 KB Created: 2019-05-07 04:36:23 +01:00 Authoring application: mPDF 5.7
MD5: e314fb940cafbfd6f7ba87a1ad53cc37 SHA-1: c0c17217058667c4fa10843a6328cc52bc13a308 SHA-256: 49516a5af31dc24cc8a106814815ebeae5d25d6a80f2c48ad0451d0fa9d59205
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the primary attack pattern appears to be directing users to a multitude of external sites, likely for SEO poisoning or to host further malicious content. The URLs themselves are marked as confirmed benign, but the sheer volume and the heuristic firing suggest a malicious intent behind their distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9754

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090096092092095/Stop-Me-If-You-ve-Heard-This-One-Before-by-David-Yoo.pdf
    • http://loaminoo.linkpc.net/3091091097097090/Funny-Things-I-Heard-At-The-Bus-Stop-Volume-1-by-Angela-Giroux.pdf
    • http://loaminoo.linkpc.net/9090093097095095/The-First-Time-I-Heard-David-Bowie-by-Scott-Heim.pdf
    • http://loaminoo.linkpc.net/1094090095090096/The-Man-Who-Couldn-t-Stop-by-David-Adam.pdf
    • http://loaminoo.linkpc.net/1095091099099/Stop-Nuclear-War-A-Handbook-by-David-Philip-Barash.pdf
    • http://loaminoo.linkpc.net/9094099091093098/Fight-for-Your-Money-How-to-Stop-Getting-Ripped-Off-and-Save-a-Fortune-by-David-Bach.pdf
    • http://loaminoo.linkpc.net/2095091099095097/The-Law-of-the-Garbage-Truck-How-to-Respond-to-People-Who-Dump-on-You-and-How-to-Stop-Dumping-on-Others-by-David-J-Pollay.pdf
    • http://loaminoo.linkpc.net/4090096097090095/The-Man-Who-Couldn-t-Stop-OCD-and-the-True-Story-of-a-Life-Lost-in-Thought-by-David-Adam.pdf
    • http://loaminoo.linkpc.net/5096092096097/Teenage-Murderer-Alyssa-Bustamante-True-Crime-Bus-Stop-Reads-29-by-Bus-Stop-Guides.pdf
    • http://loaminoo.linkpc.net/3093092094093/Can-t-Stop-Won-t-Stop-A-History-of-the-Hip-Hop-Generation-by-Jeff-Chang.pdf
    • http://loaminoo.linkpc.net/1090094099091093/You-Can-t-Stop-Me-You-Can-t-Stop-Me-1-by-Max-Allan-Collins.pdf
    • http://loaminoo.linkpc.net/9094097094096099/STOP-ARGUING-HOW-TO-STOP-ARGUING-PROTECT-QUALITY-TIME-PREVENT-BICKERING-PRESERVE-LOVE-ENJOY-LIFE-DEALING-WITH-DIFFICULT-TALKS-AND-SITUATIONS-THAT-ARE-COMMON-IN-RELATIONSHIPS-by-C-J-Kruse.pdf
    • http://loaminoo.linkpc.net/3098097099096097/I-Heard-the-Bells-by-Dawn-Luedecke.pdf
    • http://loaminoo.linkpc.net/2098098097092099/I-Heard-Your-Voice-by-Tanith-Davenport.pdf
    • http://loaminoo.linkpc.net/1099099099098090/What-the-Ladybird-Heard-by-Julia-Donaldson.pdf
    • http://loaminoo.linkpc.net/6090098091097091/What-the-Ladybug-Heard-by-Julia-Donaldson.pdf
    • http://loaminoo.linkpc.net/4090099099096093/And-Then-We-Heard-the-Thunder-by-John-Oliver-Killens.pdf
    • http://loaminoo.linkpc.net/4096092090092/I-Heard-That-Song-Before-by-Mary-Higgins-Clark.pdf
    • http://loaminoo.linkpc.net/8093092093093094/I-Heard-a-Bluebird-Sing-by-Aileen-Fisher.pdf
    • http://loaminoo.linkpc.net/1095090095092092/What-Edward-Heard-by-Megan-Easley-Walsh.pdf