Malicious PDF — malware analysis report

Static analysis result for SHA-256 50ea800ced78da2f…

MALICIOUS

PDF

13.9 KB Created: 2019-05-02 17:45:07 +01:00 Authoring application: mPDF 5.7
MD5: 9ab0065bb20a3b2101babef5be9faf8c SHA-1: 36e99517f5fb71d7342328124deef060806f6eb2 SHA-256: 50ea800ced78da2f1a1da313f6b3e5f933b26d339e7538acbef0c9c6a8c7fac1
98 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, a technique often used for SEO spam or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the 'PDF_SEO_LINK_FARM' heuristic confirms the presence of a link farm. While the document body contains some urgency language, the primary malicious activity appears to be the distribution of links hosted on 'loaminoo.linkpc.net'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1093090094091094/Maximum-Violence-Arisen-4-by-Glynn-James.pdf
    • http://loaminoo.linkpc.net/4098092097090093/Fortress-Britain-Arisen-1-by-Glynn-James.pdf
    • http://loaminoo.linkpc.net/1091096090097098/Fortress-Britain-Arisen-1-by-Glynn-James.pdf
    • http://loaminoo.linkpc.net/3092095095097097/Empire-of-the-Dead-Arisen-8-by-Glynn-James.pdf
    • http://loaminoo.linkpc.net/8094095/Maximum-Ride-Forever-Maximum-Ride-9-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1092094098094099/Maximum-Ride-Vol-7-Maximum-Ride-The-Manga-7-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/3094096094099/Maximum-Ride-Vol-1-Maximum-Ride-The-Manga-1-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1091095098092096/The-Broken-Lands-Diary-of-the-Displaced-2-by-Glynn-James.pdf
    • http://loaminoo.linkpc.net/5098098093096095/Maximum-Ride-The-Manga-Vol-1-Maximum-Ride-The-Manga-1-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/5098098094097093/Maximum-Ride-The-Manga-Vol-3-Maximum-Ride-The-Manga-3-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/3099091092098095/Max-Maximum-Ride-5-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1093090091091099/Max-Maximum-Ride-5-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1090096096095/Fang-Maximum-Ride-6-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/4090093098091098/Nevermore-Maximum-Ride-8-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/3098097099092093/Angel-Maximum-Ride-7-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/4092091093093099/School-s-Out---Forever-Maximum-Ride-2-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/9090092092099/The-Final-Warning-Maximum-Ride-4-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1095098097095099/School-s-Out---Forever-Maximum-Ride-2-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/3092098090096/School-s-Out-Forever-Maximum-Ride-2-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/6091097090095097/Maximum-Ridethe-Angel-Experiment-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1093090091091099/Max-Maximum-