Malicious PDF — malware analysis report

Static analysis result for SHA-256 796c5affa3adb4af…

MALICIOUS

PDF

14.6 KB Created: 2019-04-30 18:39:45 +01:00 Authoring application: mPDF 5.7
MD5: 1695410c2694ec1213295e1f3c2aac43 SHA-1: 0a284823cb603bbc5f294af29dd9ec533a33cdb5 SHA-256: 796c5affa3adb4af4e90ca02e15e734d73ba4d1ab8a2466a782a65b2d4db4d13
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a link farm or SEO manipulation tactic. While the URLs themselves are currently marked as benign, the sheer volume and the ML classifier's high confidence indicate a malicious intent. The document body, though heavily obfuscated, contains these URLs, reinforcing the attack pattern. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095091096092098/Breaking-Free-Masters-of-the-Shadowlands-3-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/8095098093096/Breaking-Free-Masters-of-the-Shadowlands-3-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/4090096099093/Club-Shadowlands-Masters-of-the-Shadowlands-1-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/8097093097094097/Club-Shadowlands-Masters-of-the-Shadowlands-1-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/8093093094099/This-is-Who-I-Am-Masters-of-the-Shadowlands-7-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/2096090093090098/Mischief-and-the-Masters-Masters-of-the-Shadowlands-12-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/2098091091091092/Make-Me-Sir-Masters-of-the-Shadowlands-5-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/4098099090093/Lean-on-Me-Masters-of-the-Shadowlands-4-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/3094091097099096/Master-of-Solitude-Mountain-Masters-amp-Dark-Haven-8-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/8097094094097/Master-of-the-Abyss-Mountain-Masters-amp-Dark-Haven-2-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/3093092098090099/Master-of-the-Dark-Side-Mountain-Masters-amp-Dark-Haven-4-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/8099098094098/Master-of-the-Mountain-Mountain-Masters-amp-Dark-Haven-1-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/1098094098098095/Master-of-the-Mountain-Mountain-Masters-amp-Dark-Haven-1-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/4097095099099/The-Starlight-Rite-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/3098097090099095/The-Starlight-Rite-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/2090096092091090/Hour-of-the-Lion-The-Wild-Hunt-Legacy-1-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/3094095091092096/Breaking-Free-Breaking-Free-1-by-Cara-Dee.pdf
    • http://loaminoo.linkpc.net/5090091093096095/Free-Air-by-Sinclair-Lewis.pdf
    • http://loaminoo.linkpc.net/1090092092091098097/Miriam---Breaking-Free-by-Ken-Rander.pdf
    • http://loaminoo.linkpc.net/3090098094091091/Breaking-Free-Guarded-2-by-Cat-Grant.pdf