Malicious PDF — malware analysis report

Static analysis result for SHA-256 76d6f8bc26258774…

MALICIOUS

PDF

19.8 KB Created: 2019-05-01 05:13:22 +01:00 Authoring application: mPDF 5.7
MD5: bd13f78c7b577c64d8b8d88b7a4e0fd0 SHA-1: 8196808221bcaaaf484f3f3ccab9a42f17f9b4a2 SHA-256: 76d6f8bc262587743880ec091d32decae2d8bbae9197e4a0c9a98264e62f1e99
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a machine learning classifier as malicious and contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM'. While the document body is heavily obfuscated and unreadable, the presence of numerous links suggests a potential attempt to distribute malicious content or engage in SEO spam. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9982

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091094098093090091/Chaotic-Be-Jack-A-Jack-Nolan-Novel-The-Cap-s-Place-Series-Book-5-by-Robert-Tarrant.pdf
    • http://loaminoo.linkpc.net/8092091090093098/jack-and-the-journey-through-time-revised-edition-jack-and-the-journey-through-time-series-Book-1-by-Manook-Sarkisyan.pdf
    • http://loaminoo.linkpc.net/1093095098096/Jack-on-the-Tracks-Four-Seasons-of-Fifth-Grade-Jack-Henry-4-by-Jack-Gantos.pdf
    • http://loaminoo.linkpc.net/1092094099094095/Action-Men-with-Silly-Putty-A-Jack-Donegal-Mystery-Jack-Donegal-Mysteries-Book-1-by-Susan-Joy-Clark.pdf
    • http://loaminoo.linkpc.net/1090092095095090092/The-Big-Silver-Book-of-Russian-Verbs-555-Fully-Conjugated-Verbs-Big-Book-of-Verbs-Series-by-Jack-Franke.pdf
    • http://loaminoo.linkpc.net/3096092093093095/Jack-Jack-You-Don-t-Know-Jacks-by-Jack-Gilinsky.pdf
    • http://loaminoo.linkpc.net/1091090095091092/Jack-of-Kinrowan-Jack-the-Giant-Killer-Drink-Down-the-Moon-by-Charles-de-Lint.pdf
    • http://loaminoo.linkpc.net/6092099092096094/F-bulas-presenta-Jack-vol-1-La-casi-gran-evasi-n-Jack-of-Fables-1-by-Bill-Willingham.pdf
    • http://loaminoo.linkpc.net/4090096092090095/The-Story-Of-Wild-Goose-Jack-The-Life-And-Work-Of-Jack-Miner-by-James-M-Linton.pdf
    • http://loaminoo.linkpc.net/1091099095091099090/Jack-and-the-Giant-Killer-Jack-Stratton-4-by-Christopher-Greyson.pdf
    • http://loaminoo.linkpc.net/4090094097098096/Jack-of-Fables-Vol-2-Jack-of-Hearts-by-Bill-Willingham.pdf
    • http://loaminoo.linkpc.net/1093091094098094/Jack-Wakes-Up-Jack-Palms-1-by-Seth-Harwood.pdf
    • http://loaminoo.linkpc.net/2095095099093096/The-Jack-amp-Jill-Series-by-Jewel-E-Ann.pdf
    • http://loaminoo.linkpc.net/1091094098091093/Future-Remains-by-Robert-Jack.pdf
    • http://loaminoo.linkpc.net/8090099098091095/English-Authors-Series-Ian-McEwan-by-Jack-Slay-Jr-.pdf
    • http://loaminoo.linkpc.net/6090092093098095/Days-of-Panic-EMP-Survival-Series-1-by-Jack-Hunt.pdf
    • http://loaminoo.linkpc.net/1090092092096099/Jack-Canfield-s-Key-to-Living-the-Law-of-Attraction-A-Simple-Guide-to-Creating-the-Life-of-Your-Dreams-by-Jack-Canfield.pdf
    • http://loaminoo.linkpc.net/2090094099091096/Trust-Me-Jack-s-Beanstalk-Stinks-The-Story-of-Jack-and-the-Beanstalk-as-Told-by-the-Giant-by-Eric-Braun.pdf
    • http://loaminoo.linkpc.net/2091098098098093/Bloodletting-Book-4-1---Jack-by-Joe-Humphrey.pdf
    • http://loaminoo.linkpc.net/2090096093097093/Book-of-Sketches-by-Jack-Kerouac.pdf
    • http://loaminoo.linkpc.net/1090092095095090092/The-Big-Silver-Book-of-Russian-Verbs-555-Fully-Conjugated-Verbs-Big-B