Malicious PDF — malware analysis report

Static analysis result for SHA-256 589a54409d740a07…

MALICIOUS

PDF

16.7 KB Created: 2019-04-30 04:28:22 +01:00 Authoring application: mPDF 5.7
MD5: 10ef5d6eba1f4289557710730fbc03f8 SHA-1: 6bbd7f8ec151607689d1a4b4b5a676f69168acef SHA-256: 589a54409d740a0721fbd9cbba62cc6bd1c6474f047c34c757791f937ea9205f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, which is indicative of a link farm or redirection scheme. The ML_NYX_PDF_MALICIOUS classifier also flagged this sample with high confidence. While no scripts were extracted, the embedded URLs suggest a social engineering tactic to lure users to download content, potentially leading to further malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092099098092090/The-Richard-Laymon-Collection-Volume-1-The-Beast-House-Trilogy-The-Cellar---The-Beast-House---The-Midnight-Tour-Richard-Laymon-Collection-1-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/1097096093093099/The-Midnight-Tour-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/1096095096094092/The-Cellar-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/2091095097095092/After-Midnight-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/3097099091093098/Fiends-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/2091098096093091/Bite-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/2098095092097092/Island-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/4093090099091/Endless-Night-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/3097097092094090/Resurrection-Dreams-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/1091097093095092/One-Rainy-Night-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/2091091092098098/The-Traveling-Vampire-Show-by-Richard-Laymon.pdf
    • http://loaminoo.linkpc.net/2092097096099099/Long-Division-by-Kiese-Laymon.pdf
    • http://loaminoo.linkpc.net/4098090094090098/Richard-Scarry-s-Great-Steamboat-Mystery-The-Best-Book-Club-Ever-A-Random-House-Picture-Book-by-Richard-Scarry.pdf
    • http://loaminoo.linkpc.net/3090093097090093/Bruiser-by-Richard-House.pdf
    • http://loaminoo.linkpc.net/6090090090095/The-Patchwork-House-by-Richard-Salter.pdf
    • http://loaminoo.linkpc.net/1098092094096099/Doctor-In-The-House-by-Richard-Gordon.pdf
    • http://loaminoo.linkpc.net/1095094092096098/Hell-House-by-Richard-Matheson.pdf
    • http://loaminoo.linkpc.net/1091094098093090093/Hell-House-by-Richard-Matheson.pdf
    • http://loaminoo.linkpc.net/6098090092090098/Works-by-Richard-Matheson-Novels-by-Richard-Matheson-Screenplays-by-Richard-Matheson-Short-Stories-by-Richard-Matheson-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/6098090092094092/Richard-Matheson-s-Hell-House-by-Ian-Edginton.pdf
    • http://loaminoo.linkpc.net/3