Malicious PDF — malware analysis report

Static analysis result for SHA-256 548f75671f85ed47…

MALICIOUS

PDF

23.1 KB Created: 2019-05-02 17:40:16 +01:00 Authoring application: mPDF 5.7
MD5: abbdad295dca85ea558f38754591249f SHA-1: 8c4d87cbbcace5b780a40da286ce2f9440de3672 SHA-256: 548f75671f85ed470668a924561eacb443489736047fa96acbd623315a33149e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malware. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3095096099097097/Saturday-Night-Live-The-Book-by-Alison-Castle.pdf
    • http://loaminoo.linkpc.net/1091093094095093091/Gasping-for-Airtime-Two-Years-in-the-Trenches-of-Saturday-Night-Live-by-Jay-Mohr.pdf
    • http://loaminoo.linkpc.net/7093090095092096/The-History-of-Saturday-Night-Live-2005-2010-Starring-Tina-Fey-Andy-Samberg-and-Kenan-Thompson-by-Jenny-Reese.pdf
    • http://loaminoo.linkpc.net/1091097090091093099/Saturday-Story-Prompts-Collection-2013-Saturday-Story-Prompts-Yearly-Collections-Book-4-by-Martha-Bechtel.pdf
    • http://loaminoo.linkpc.net/4094095092093091/Saturday-Night-by-Susan-Orlean.pdf
    • http://loaminoo.linkpc.net/1091092098099090/Saturday-Night-by-Caroline-B-Cooney.pdf
    • http://loaminoo.linkpc.net/4094095097095096/The-Saturday-Night-Supper-Club-by-Carla-Laureano.pdf
    • http://loaminoo.linkpc.net/5090099091093/Sweet-Home-Saturday-Night-Poems-by-David-Baker.pdf
    • http://loaminoo.linkpc.net/8098096094090090/The-Secret-Saturdays---Characters-Abbey-Grey-Agent-Epsilon-Arthur-Beeman-Baron-Finster-Chonos-Khan-Deadbolt-Doc-Monday-Doc-Saturday-Doyle-Blackwell-Dr-Lee-Drew-Monday-Drew-Saturday-Elija-Saturday-Eterno-Fisk-Robots-Fiskerton-Fisk-Satur-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/1092091099098093/The-Last-Saturday-Of-October-The-Declassified-Secrets-of-Black-Saturday-by-Douglas-Charles-Gilbert.pdf
    • http://loaminoo.linkpc.net/3099093096094096/Saturday-Night-Cleaver-A-Barbara-Marr-Murder-Mystery-4-by-Karen-Cantwell.pdf
    • http://loaminoo.linkpc.net/3099090099092092/Saturday-Night-Peter-Memoirs-of-a-Stand-Up-Comedian-by-Kay-Peter.pdf
    • http://loaminoo.linkpc.net/4093095096094099/Castle-Darkest-Night-by-Joe-Vadalma.pdf
    • http://loaminoo.linkpc.net/1095096096095/The-Saturday-Night-Special-And-Other-Guns-with-which-Americans-won-the-West-Protected-Bootleg-Franchises-Slew-Wildlife-Robbed-Countless-Banks-Shot-with-the-Debate-Over-Continuing-Same-by-Robert-Sherrill.pdf
    • http://loaminoo.linkpc.net/1090095099098099/The-Night-Watchman-Express-The-Crown-Phoenix-1-by-Alison-DeLuca.pdf
    • http://loaminoo.linkpc.net/5091099098098091/Spanish-Castle-to-White-Night-by-Mark-Chisnell.pdf
    • http://loaminoo.linkpc.net/4098095099091090/The-Moneyless-Manifesto-Live-Well-Live-Rich-Live-Free-by-Mark-Boyle.pdf
    • http://loaminoo.linkpc.net/1096093096094/Live-by-Night-Coughlin-2-by-Dennis-Lehane.pdf
    • http://loaminoo.linkpc.net/8092098095093095/Summary-amp-Study-Guide-Live-By-Night-by-Dennis-Lehane-by-BookRags.pdf
    • http://loaminoo.linkpc.net/1091097091098095096/Regan-s-Recovery-Castle-Phantasie-Book-2-by-Kit-Tunstall.pdf
    • http://loaminoo.linkpc.net/1091092098099090/Saturday-Night-by-Ca