Malicious PDF — malware analysis report

Static analysis result for SHA-256 585875d1567bc43c…

MALICIOUS

PDF

24.6 KB Created: 2019-05-02 05:27:49 +01:00 Authoring application: mPDF 5.7
MD5: b7f10d78f68fd57216dd227a80a26bc8 SHA-1: b12464ffcb20542970a338afa36aa5466cc46c45 SHA-256: 585875d1567bc43c72ed33e8818e2b48e0c82e04abf0dfe70907a67db313e940
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, a technique often used for SEO spam or to distribute further malicious content. While no scripts were extracted, the sheer volume of links and the ML classification suggest a malicious intent, likely to lure users to malicious sites or to manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090097090093095096/Super-Science-Fiction-by-Stephen-Haffner.pdf
    • http://loaminoo.linkpc.net/4090090094099096/Astounding-Stories-of-Super-Science-January-1930-by-Harry-Bates.pdf
    • http://loaminoo.linkpc.net/1090091092094096097/Lubek-s-Threelogy-the-Sweet-Science-2-S-Rocky-The-Brockton-Blockbuster-50-0--Classic-Boxing-II-the-Super-One---Was-It-a-Murder-or-Suicide-III-the-History-of-Reproducing-Piano-Rolls-by-Jan-Lubek.pdf
    • http://loaminoo.linkpc.net/1091091099099093096/The-Super-Collection-Super-Series-by-Princess-Jones.pdf
    • http://loaminoo.linkpc.net/4099096097091095/Searching-for-Super-Almost-Super-2-by-Marion-Jensen.pdf
    • http://loaminoo.linkpc.net/3097099097090096/Almost-Super-Almost-Super-1-by-Marion-Jensen.pdf
    • http://loaminoo.linkpc.net/1096092090090090/The-Super-Spies-and-the-High-School-Bomber-Super-Spies-2-by-Lisa-Orchard.pdf
    • http://loaminoo.linkpc.net/9093092092095090/DC-Super-Friends-Volume-2-Calling-All-Super-Friends-by-Sholly-Fisch.pdf
    • http://loaminoo.linkpc.net/2099094098091099/Super-Powereds-Year-4-Super-Powereds-4-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/9093092093090097/DC-Super-Friends-Wanted-The-Super-Friends-by-Sholly-Fisch.pdf
    • http://loaminoo.linkpc.net/2092092091099092/Super-Powereds-Year-3-Super-Powereds-3-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/7094095094092092/Science-Projects-for-Kids-Making-Science-Fun-in-10-Minutes-or-Less-21-Science-Experiments-For-Kids-Ages-9---12-by-JoJo-Sabra.pdf
    • http://loaminoo.linkpc.net/3097094091099091/Super-Powers-Vol-1-DC-Kids-Super-Powers-1-by-Art-Baltazar.pdf
    • http://loaminoo.linkpc.net/1090095095097098093/Unsolved-Problems-of-Co--And-Graft-Polymerization-Proceedings-of-the-First-S-R-Romanian-U-S-Seminar-on-Polymer-Science-Held-Under-the-Sponsorship-of-the-Romanian-National-Council-for-Science-and-Technology-Ncst-and-the-U-S-National-Science-Found-by-Otto-Vogl.pdf
    • http://loaminoo.linkpc.net/1095099097091091/From-Neurons-to-Neighborhoods-The-Science-of-Early-Childhood-Development-by-Committee-on-Integrating-the-Science-of.pdf
    • http://loaminoo.linkpc.net/9098096090097093/Through-the-Shadowlands-A-Science-Writer-s-Odyssey-into-an-Illness-Science-Doesn-t-Understand-by-Julie-Rehmeyer.pdf
    • http://loaminoo.linkpc.net/2093099090094097/The-Science-of-Harry-Potter-The-Spellbinding-Science-Behind-the-Magic-Gadgets-Potions-and-More-by-Mark-Brake.pdf
    • http://loaminoo.linkpc.net/7090092096095094/Visual-Cultures-of-Science-Rethinking-Representational-Practices-in-Knowledge-Building-and-Science-Communication-by-Luc-Pauwels.pdf
    • http://loaminoo.linkpc.net/4094097098093090/Science-Is-Culture-Conversations-at-the-New-Intersection-of-Science-Society-by-Adam-Bly.pdf
    • http://loaminoo.linkpc.net/4092099093094094/Alchemy-Science-of-the-Cosmos-Science-of-the-Soul-by-Titus-Burckhardt.pdf