Malicious PDF — malware analysis report

Static analysis result for SHA-256 59b9d18efc6fa902…

MALICIOUS

PDF

16.8 KB Created: 2019-04-30 03:48:09 +01:00 Authoring application: mPDF 5.7
MD5: 26ddd878eee9e6d38443e32cfff9bf34 SHA-1: 58e7ffed5ba8d4109b1b04fe0ec01b1c72921356 SHA-256: 59b9d18efc6fa9028031c36509cf37b1b5f6326b37f545153ae2e230d5e5a11f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links to external resources, many of which are benign, suggests a potential distribution or SEO manipulation tactic. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3092091096093098/The-Wanderer-by-Sharon-Creech.pdf
    • http://loaminoo.linkpc.net/1094091093093099/The-Wanderer-by-Sharon-Creech.pdf
    • http://loaminoo.linkpc.net/3098099096093/Bloomability-by-Sharon-Creech.pdf
    • http://loaminoo.linkpc.net/7099093095091/The-Castle-Corona-by-Sharon-Creech.pdf
    • http://loaminoo.linkpc.net/2099098098093095/Walk-Two-Moons-by-Sharon-Creech.pdf
    • http://loaminoo.linkpc.net/4096098096095/Absolutely-Normal-Chaos-by-Sharon-Creech.pdf
    • http://loaminoo.linkpc.net/2097099096098092/Absolutely-Normal-Chaos-by-Sharon-Creech.pdf
    • http://loaminoo.linkpc.net/3091090096097093/The-Soup-Sisters-Cookbook-100-Simple-Recipes-to-Warm-Hearts-One-Bowl-at-a-Time-by-Sharon-Hapton.pdf
    • http://loaminoo.linkpc.net/3097096090092097/9x-Fun-A-Children-s-Picture-Book-That-Makes-Math-Fun-with-a-Cartoon-Story-Format-to-Help-Kids-Learn-the-9x-Table-by-Sharon-Clark.pdf
    • http://loaminoo.linkpc.net/4091095091091091/Chicken-Soup-Teenage-Trilogy-Chicken-Soup-for-the-Soul-by-Jack-Canfield.pdf
    • http://loaminoo.linkpc.net/2095095093093098/Chicken-Soup-for-the-Father-and-Daughter-Soul-Stories-to-Celebrate-the-Love-Between-Dads-and-Daughters-Throughout-the-Years-Chicken-Soup-for-the-Soul-by-Jack-Canfield.pdf
    • http://loaminoo.linkpc.net/3091091091094091/Cooking-with-Soup-A-Campbell-Cookbook-by-Campbell-Soup-Company.pdf
    • http://loaminoo.linkpc.net/2096090099090092/Alphabet-Soup-Alphabet-Soup-1-Russian-Bear-2-by-C-B-Conwy.pdf
    • http://loaminoo.linkpc.net/3093094095098091/The-Whole-Way-Home-by-Sarah-Creech.pdf
    • http://loaminoo.linkpc.net/3094091099096092/Season-of-the-Dragonflies-by-Sarah-Creech.pdf
    • http://loaminoo.linkpc.net/4093095096099/Granny-Dan-by-Danielle-Steel.pdf
    • http://loaminoo.linkpc.net/1096096098094095/What-Cried-Granny-by-Kate-Lum.pdf
    • http://loaminoo.linkpc.net/7099093099095091/Under-the-Gun-Granny-Series-4-by-Kelsey-Browning.pdf
    • http://loaminoo.linkpc.net/1090098093097098090/Granny-Rainbow-by-Katherine-Hetzel.pdf
    • http://loaminoo.linkpc.net/4095093093096/Gangsta-Granny-by-David-Walliams.pdf
    • http://loaminoo.linkpc.net/3097096090092097/9x-Fun-A-Children-s-Picture-Book-That-Makes-Math-Fun-with-a-Cartoon-Story-Format-to-Help-Kids-Learn-the-9x-Table-by-Sharon-Clark.p