Malicious PDF — malware analysis report

Static analysis result for SHA-256 52d54c519c4afef9…

MALICIOUS

PDF

20.3 KB Created: 2019-04-30 02:33:35 +01:00 Authoring application: mPDF 5.7 First seen: 2019-05-31
MD5: f01f29b5195f2f5cdedf54c1b422fe9f SHA-1: c89217f5d7c3aebd66dad3675a257d7ed855b26e SHA-256: 52d54c519c4afef9ba2c3b225faeff1fefaa246ea32aec0368fc627cf32fdf1e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to recovery-related books and are marked as benign, the sheer volume and the ML_NYX_PDF_MALICIOUS classification suggest a malicious intent, likely to manipulate search engine results or distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099091098093091/My-Five-Year-Recovery-Planner-Looking-to-the-Future-One-Day-at-a-Time-by-Central-Recovery-Press.pdf In PDF document text
    • http://loaminoo.linkpc.net/2099091098093093/Recovery-A-to-Z-A-Handbook-of-Twelve-Step-Key-Terms-and-Phrases-by-Central-Recovery-Press.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2099091098093094/My-Pain-Recovery-Journal-by-Central-Recovery-Press.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9093099091096096/Chi-Kung-in-Recovery-Finding-Your-Way-to-a-Balanced-and-Centered-Recovery-by-Gregory-Pergament.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4099094093092093/My-Recovery-Inspiring-Stories-Recovery-Tips-And-Messages-Of-Hope-From-Eating-Disorder-Survivors-by-Julie-Parker.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3097095092091093/American-Rebirth-Civil-War-National-Recovery-and-Prosperity-Sisters-in-Time-13-16-by-Norma-Jean-Lutz.pdfIn PDF document text
    • http://loaminoo.linkpc.net/9093092099092/3-Steps-to-Recovery-by-Dan-Farish.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090090097099091096/The-Recovery-of-Truth-by-Hermann-Keyserling.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6096096091/Recovery-Freedom-from-Our-Addictions-by-Russell-Brand.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7092096099093090/Recovery-in-Mental-Health-by-Michaela-Amering.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4099094091093099/Bulimia-A-Guide-to-Recovery-by-Lindsey-Hall.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1090090093094091099/Adoption-Healing-a-path-to-recovery-by-Joe-Soll.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4099093097093098/Sensing-the-Self-Women-s-Recovery-from-Bulimia-by-Sheila-M-Reindl.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091099093095098/Starfish-A-Mother-s-Recovery-from-Addiction-by-Donna-M-George.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4099094091094096/The-ABCs-of-Recovery-from-Mental-Illness-by-Carol-A-Kivler.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091097091098095096/Regan-s-Recovery-Castle-Phantasie-Book-2-by-Kit-Tunstall.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7094093093091095/Oracle8i-Backup-and-Recovery-24seven-by-James-Coopman.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091099095093095094/Getting-Up-Getting-Over-Getting-on-A-12-Step-Guide-to-Divorce-Recovery-by-Micki-McWade.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2099091093092091/Why-Don-t-They-Just-Quit-What-Families-and-Friends-Need-to-Know-about-Addiction-and-Recovery-by-Joe-Herzanek.pdfIn PDF document text
    • http://loaminoo.linkpc.net/6092099091095093/U-S-Army-Survival-Evasion-and-Recovery-by-U-S-Department-of-Defense.pdfIn PDF document text