Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f04b55ad5f51b0a…

MALICIOUS

PDF

21.6 KB Created: 2019-05-05 15:42:15 +01:00 Authoring application: mPDF 5.7
MD5: 9fbd60771efe7fd2e7d167a4cf8f42a3 SHA-1: 87856dc8648e4af43420202bed290a7b42fc0956 SHA-256: 4f04b55ad5f51b0a23cc78724f22b489f9664f52a52aa812f0c3b5ce724eeb95
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs are marked as confirmed benign, the sheer volume and structure suggest a link farm or redirection mechanism. The ML classifier also strongly indicated maliciousness. The document body is heavily obfuscated and unreadable, preventing a more detailed analysis of its specific lure, but the overall pattern points to a malicious PDF designed to redirect users to external content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090098096097097/The-Girls-Book-3-Even-More-Ways-To-Be-The-Best-At-Everything-Girls-Book-by-Tracey-Turner.pdf
    • http://loaminoo.linkpc.net/8093090099092099/9-Ways-We-re-Screwing-Up-Our-Girls-and-How-We-Can-Stop-A-Guide-to-Helping-Girls-Reach-Their-Highest-Potential-by-Anea-Bogue.pdf
    • http://loaminoo.linkpc.net/4091094098096093/Hometown-Girls-Reunion-Hometown-Girls-Series-Book-2-by-Tressa-Messenger.pdf
    • http://loaminoo.linkpc.net/3091091092096096/Girls-to-the-Rescue-Book-5-Girls-to-the-Rescue-5-by-Bruce-Lansky.pdf
    • http://loaminoo.linkpc.net/3091092090098099/Girls-to-the-Rescue-Book-4-Girls-to-the-Rescue-4-by-Bruce-Lansky.pdf
    • http://loaminoo.linkpc.net/4091099091098094/--LOST-GIRLS-1-Shingeki-no-Kyojin-Lost-Girls-1-Attack-on-Titan-Lost-Girls-Manga-1-by-Hajime-Isayama.pdf
    • http://loaminoo.linkpc.net/1099098099093095/The-Naughty-Girls-Book-Club-by-Sophie-Hart.pdf
    • http://loaminoo.linkpc.net/4095098096096091/Becca-by-the-Book-Getaway-Girls-3-by-Laura-Jensen-Walker.pdf
    • http://loaminoo.linkpc.net/7091098094097099/Stitches-And-Pins-A-Beginning-Sewing-Book-For-Girls-by-JoAnn-Gagnon.pdf
    • http://loaminoo.linkpc.net/1096093090093099/Codename-Night-Witch-The-Girls-from-Alcyone-Book-3-by-Cary-Caffrey.pdf
    • http://loaminoo.linkpc.net/2097095093098091/The-Care-and-Keeping-of-You-The-Body-Book-for-Younger-Girls-by-Valorie-Schaefer.pdf
    • http://loaminoo.linkpc.net/3098091094095098/The-Romancing-of-Evangeline-Ipswich-Three-Little-Girls-Dressed-in-Blue-Book-3-by-Marcia-Lynn-McClure.pdf
    • http://loaminoo.linkpc.net/7091092099091091/Goth-Girls-Don-t-Taste-Like-Chicken-Me-and-My-Friend-Maddie-Gothic-Book-Series-1-by-Robert-Tomoguchi.pdf
    • http://loaminoo.linkpc.net/2094099096091091/Glitter-Girls-and-the-Great-Fake-Out-Allie-Finkle-s-Rules-for-Girls-5-by-Meg-Cabot.pdf
    • http://loaminoo.linkpc.net/6097093091091090/No-More-Mean-Girls-The-Secret-to-Raising-Strong-Confident-and-Compassionate-Girls-by-Katie-Hurley.pdf
    • http://loaminoo.linkpc.net/3091093094090093/Glitter-Girls-and-the-Great-Fake-Out-Allie-Finkle-s-Rules-for-Girls-5-by-Meg-Cabot.pdf
    • http://loaminoo.linkpc.net/7098091094095093/Bad-Girls-Why-Men-Love-Them-amp-How-Good-Girls-Can-Learn-Their-Secrets-by-Carole-Lieberman.pdf
    • http://loaminoo.linkpc.net/6097093090093094/Girls-Will-Be-Girls-Raising-Confident-and-Courageous-Daughters-by-JoAnn-Deak.pdf
    • http://loaminoo.linkpc.net/3097098094094090/The-Munitions-Girls-The-Bomb-Girls-1-by-Rosie-Archer.pdf
    • http://loaminoo.linkpc.net/3095094095097092/Where-Bad-Girls-Go-to-Fall-Good-Girls-2-by-Holly-Renee.pdf
    • http://loaminoo.linkpc.net/4091099091098094/--LOST-GIRLS-1-Shingeki-no-Kyojin-Lost-Girls-1-Attack-on-Titan-Lost-Girls-Mang