Malicious PDF — malware analysis report

Static analysis result for SHA-256 59d0d56436e3d1be…

MALICIOUS

PDF

17.0 KB Created: 2019-05-01 22:07:13 +01:00 Authoring application: mPDF 5.7
MD5: 06b31c11c8f38a3e008ce3685e3ec45a SHA-1: 3e89df00495d21f8787391b426437cb8a256d935 SHA-256: 59d0d56436e3d1be852cb68f73f6da463888e2cc31c6154c0ecb8747c61cc90f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, forming a link farm, with the primary URL being http://loaminoo.linkpc.net/1091091099094094092/Doctor-Doctor-Part-Two-Doctors-Orders-Series-by-Kassandra-Cox.pdf. This suggests the document's purpose is to redirect users to potentially harmful content or facilitate SEO spam.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091091099094094092/Doctor-Doctor-Part-Two-Doctors-Orders-Series-by-Kassandra-Cox.pdf
    • http://loaminoo.linkpc.net/3096095099097097/Doctor-Who-2015-Event-The-Four-Doctors-2-Doctor-Who-2015-Event-Four-Doctors-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/4099092096096097/Doctor-Who-The-Tenth-Doctor-Adventures-10th-Doctor-Audio-Originals-by-Peter-Anghelides.pdf
    • http://loaminoo.linkpc.net/4090092097097099/Doctor-s-Orders-by-Lucy-Felthouse.pdf
    • http://loaminoo.linkpc.net/3092090099092095/Doctor-Who-and-the-Three-Doctors-by-Terrance-Dicks.pdf
    • http://loaminoo.linkpc.net/8098099093098/Doctor-Who-The-Eight-Doctors-by-Terrance-Dicks.pdf
    • http://loaminoo.linkpc.net/2091091091093098/Doctor-Who-Timeframe-The-Illustrated-History-Doctor-Who-30th-Anniversary-by-David-J-Howe.pdf
    • http://loaminoo.linkpc.net/3095091092093094/Curing-Doctor-Vincent-The-Good-Doctor-Trilogy-1-by-Renea-Mason.pdf
    • http://loaminoo.linkpc.net/2090096092094091/Surviving-Doctor-Vincent-The-Good-Doctor-Trilogy-2-by-Renea-Mason.pdf
    • http://loaminoo.linkpc.net/4091091090098096/Doctor-Who-The-Tenth-Doctor-Vol-2-The-Weeping-Angels-of-Mons-by-Robbie-Morrison.pdf
    • http://loaminoo.linkpc.net/6093091098096090/Doctor-Who-Time-Reaver-The-Tenth-Doctor-Adventures-1-2-by-Jenny-T-Colgan.pdf
    • http://loaminoo.linkpc.net/4090098099097093/Doctor-Who-The-Ninth-Doctor-Vol-1-Weapons-of-Past-Destruction-by-Cavan-Scott.pdf
    • http://loaminoo.linkpc.net/1094097092092099/Doctor-Who-The-Twelfth-Doctor-Complete-Year-One-by-Robbie-Morrison.pdf
    • http://loaminoo.linkpc.net/1094097094091096/Doctor-Who-The-Third-Doctor-Volume-1-The-Heralds-of-Destruction-by-Paul-Cornell.pdf
    • http://loaminoo.linkpc.net/5095090093098098/Doctor-Who-Shadow-of-Death-Destiny-of-the-Doctor-2-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/5097093098092090/Doctor-Who-The-Day-She-Saved-the-Doctor-Four-Stories-from-the-TARDIS-by-Susan-Calman.pdf
    • http://loaminoo.linkpc.net/3097095096094091/Doctor-How-and-the-Illegal-Aliens-Doctor-How-1-by-Mark-Speed.pdf
    • http://loaminoo.linkpc.net/1090091098095096092/Doctor-Who-The-Seventh-Doctor-1-Operation-Volcano-by-Ben-Aaronovitch.pdf
    • http://loaminoo.linkpc.net/1094097091093094/Doctor-Who-The-Ninth-Doctor-Vol-4-Sin-Eaters-by-Cavan-Scott.pdf
    • http://loaminoo.linkpc.net/1090097092090096090/Doctor-How-and-the-Illegal-Aliens-Doctor-How-1-by-Mark-Speed.pdf
    • http://loaminoo.linkpc.net/2091091091093098/Doctor-Who-Timeframe-The-Illustrated-History-Doctor-Who-30th-Annive