Malicious PDF — malware analysis report

Static analysis result for SHA-256 587b087c374beb86…

MALICIOUS

PDF

18.0 KB Created: 2019-04-29 23:33:38 +01:00 Authoring application: mPDF 5.7
MD5: c7032052d342d99f14af4eb4a5dc1d1d SHA-1: 6753638c540b1cade67f9832ec0eb74b93c8d556 SHA-256: 587b087c374beb8641d09b4fefe963e719d2716a7c29861b37f925728edc6dc8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates these links are likely used for SEO manipulation or to distribute further malicious content. While no scripts were extracted, the sheer volume of links and the ML classification suggest a malicious intent, possibly related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/2090097091092095/Endless-Possibility-Rush-1-5-by-Emma-Scott.pdf
    • http://loaminoo.linkpc.net/4094098090091093/Big-Enough-for-Five-Love-is-Endless-1-by-Willa-Okati.pdf
    • http://loaminoo.linkpc.net/2092095091098/Home-Again-Endless-Love-1-by-Kathleen-Shoop.pdf
    • http://loaminoo.linkpc.net/1090099098093091092/Endless-Love-Letter-Love-Letter-2-by-Callie-Anderson.pdf
    • http://loaminoo.linkpc.net/1099098093090098/Dragon-in-the-System-Geek-Love-1-by-Cindy-Spencer-Pape.pdf
    • http://loaminoo.linkpc.net/2096090093097098/Eden-It-s-an-Endless-World-Volume-1-Eden-It-s-an-Endless-World-1-by-Hiroki-Endo.pdf
    • http://loaminoo.linkpc.net/7093093090096092/The-Medici-Aesop-Spencer-MS-50-from-the-Spencer-Collection-of-the-New-York-Public-Library-by-Aesop.pdf
    • http://loaminoo.linkpc.net/3092096095096098/Crazy-For-The-Cowboy-Love-at-the-Crazy-H-2-by-Cindy-Spencer-Pape.pdf
    • http://loaminoo.linkpc.net/3095097090092093/Love-Is-In-The-Hallways-Love-2-by-R-J-Scott.pdf
    • http://loaminoo.linkpc.net/1099092095092090/Love-For-All-Seasons-by-R-J-Scott.pdf
    • http://loaminoo.linkpc.net/5098099096092092/Love-Just-Happens-by-Elizabeth-Scott.pdf
    • http://loaminoo.linkpc.net/9096095097093/Love-Me-While-I-m-Gone-Half-of-Me-2-by-Diana-T-Scott.pdf
    • http://loaminoo.linkpc.net/9090094091091097/The-Summer-of-Love-and-War-by-Scott-Freiheit.pdf
    • http://loaminoo.linkpc.net/9097096091093/The-Love-of-the-Last-Tycoon-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/4092098095091098/I-Love-Brock-Turner-by-Scott-Hughes.pdf
    • http://loaminoo.linkpc.net/4093090090092097/Mine-A-Love-Story-by-Scott-Prussing.pdf
    • http://loaminoo.linkpc.net/1091098099099090098/Flappers-and-Philosophers-1920-by-Francis-Scott-Fitzgerald-Francis-Scott-Key-Fitzgerald-September-24-1896---December-21-1940-Known-Professionally-as-F-Scott-Fitzgerald-Was-an-American-Novelist-and-Short-Story-Writer-Whose-Works-Illustrate-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/8098094098091098/Crazy-Sexy-Love-Dive-Bar-1-by-Kylie-Scott.pdf
    • http://loaminoo.linkpc.net/4098098090091094/Lord-Borin-s-Secret-Love-by-Regina-Scott.pdf
    • http://loaminoo.linkpc.net/4096090092094097/My-Life-My-Love-My-Legacy-by-Coretta-Scott-King.pdf