Malicious PDF — malware analysis report

Static analysis result for SHA-256 59cdfba008e25543…

MALICIOUS

PDF

16.8 KB Created: 2019-05-01 18:31:52 +01:00 Authoring application: mPDF 5.7
MD5: 1ebea575786c47a9be4d2804503d80f0 SHA-1: abea9e3c9e7b2962e0e06d5dac66274199b5c36b SHA-256: 59cdfba008e255435887f259de5b9214e75cabf7bab32513ef101dd130c349f2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external websites, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these URLs are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a landing page for further malicious activity. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099096090093091/The-Woman-Who-Rides-Like-a-Man-Song-of-the-Lioness-3-by-Tamora-Pierce.pdf
    • http://loaminoo.linkpc.net/7099092097096/The-Seduction-of-Christianity-by-Dave-Hunt.pdf
    • http://loaminoo.linkpc.net/4099095091091091/Mind-Invaders-by-Dave-Hunt.pdf
    • http://loaminoo.linkpc.net/8094099092098/A-Cup-of-Trembling-Jerusalem-and-Bible-Prophecy-by-Dave-Hunt.pdf
    • http://loaminoo.linkpc.net/2095097099099090/Cosmos-Creator-and-Human-Destiny-Answering-Darwin-Dawkins-and-the-New-Atheists-by-Dave-Hunt.pdf
    • http://loaminoo.linkpc.net/3095096099096097/Honey-for-a-Woman-s-Heart-Growing-Your-World-through-Reading-Great-Books-by-Gladys-M-Hunt.pdf
    • http://loaminoo.linkpc.net/2090094091092098/Isabelle-and-the-Beast-A-Retelling-of-Beauty-and-the-Beast-by-Dee-J-Stone.pdf
    • http://loaminoo.linkpc.net/2099097090092099/Beast-Part-Two-Beast-2-by-Ella-James.pdf
    • http://loaminoo.linkpc.net/4094093098096092/Beautiful-Beast-Beast-3-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/7098091093098092/Dave-s-Dinners-A-Fresh-Approach-to-Home-Cooked-Meals-by-Dave-Lieberman.pdf
    • http://loaminoo.linkpc.net/6097098093098092/My-Story-A-Child-Called-It-The-Lost-Boy-A-Man-Named-Dave-by-Dave-Pelzer.pdf
    • http://loaminoo.linkpc.net/4096099098097090/Bike-Boy-Rides-Again-by-Zack.pdf
    • http://loaminoo.linkpc.net/1090090095097099/Davy-Jones-amp-the-Heart-of-Darkness-Includes-an-Appendix-2-Essays-from-the-Cave-of-Cinema-Dave-by-Dave-Montalbano.pdf
    • http://loaminoo.linkpc.net/3091095090093094/A-Man-Rides-Through-Mordant-s-Need-2-by-Stephen-R-Donaldson.pdf
    • http://loaminoo.linkpc.net/1098093098092094/The-Beast-Within-The-Beast-Within-1-by-Melissa-Crowe.pdf
    • http://loaminoo.linkpc.net/6093097095096092/The-Hunt-Club-Wyatt-Hunt-1-by-John-Lescroart.pdf
    • http://loaminoo.linkpc.net/1091093098096090/Super-Cowboy-Rides-by-Daris-Howard.pdf
    • http://loaminoo.linkpc.net/4090096098099092/Martin-Rides-the-Moor-by-Vian-Smith.pdf
    • http://loaminoo.linkpc.net/3096094095093093/Super-Cowboy-Rides-by-Daris-Howard.pdf
    • http://loaminoo.linkpc.net/1094091095097093/One-Leaf-Rides-the-Wind-by-Celeste-Davidson-Mannis.pdf