Malicious PDF — malware analysis report

Static analysis result for SHA-256 810548517e988b4b…

MALICIOUS

PDF

16.8 KB Created: 2019-05-02 17:55:45 +01:00 Authoring application: mPDF 5.7
MD5: b596979ff74aeae801dbbe7d544496e2 SHA-1: 8f2d774d1f50864a527bbd43810c4475982e6fe1 SHA-256: 810548517e988b4b425aa92e7cdc58a29ec76891adda562e369af7149dceac32
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. This heuristic, combined with the ML classifier and ClamAV detection, strongly suggests a malicious intent to redirect users to potentially harmful content. The embedded URLs are likely part of a phishing or content-luring scheme. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7127808-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7127808-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5091096094099099/Kristen-Kish-Cooking-Recipes-and-Techniques-by-Kristen-Kish.pdf
    • http://loaminoo.linkpc.net/2090095097090095/Geek---Boy-Equals-by-Kish-Knight.pdf
    • http://loaminoo.linkpc.net/8090097096092099/Florence-Kelley-and-the-Nation-s-Work-The-Rise-of-Women-s-Political-Culture-1830-1900-by-Kathryn-Kish-Sklar.pdf
    • http://loaminoo.linkpc.net/5093090096095090/Bonjour-Kale-A-Memoir-of-Paris-Love-and-Recipes-by-Kristen-Beddard.pdf
    • http://loaminoo.linkpc.net/5092097096098094/Julia-s-Kitchen-Wisdom-Essential-Techniques-and-Recipes-from-a-Lifetime-of-Cooking-by-Julia-Child.pdf
    • http://loaminoo.linkpc.net/8090094097094094/Classical-Lebanese-Cooking-Simple-Easy-and-Unique-Lebanese-Recipes-Lebanese-Recipes-Lebanese-Cookbook-Lebanese-Cooking-Lebanese-Cuisine-Lebanese-Food-Book-1-by-Umm-Maryam.pdf
    • http://loaminoo.linkpc.net/1098098093099094/Forsaken-Daughters-of-the-Sea-1-by-Kristen-Day.pdf
    • http://loaminoo.linkpc.net/3097094093093/For-You-The-Burg-1-by-Kristen-Ashley.pdf
    • http://loaminoo.linkpc.net/3095098091093/The-Will-Magdalene-1-by-Kristen-Ashley.pdf
    • http://loaminoo.linkpc.net/5097090098/Complicated-by-Kristen-Ashley.pdf
    • http://loaminoo.linkpc.net/3098099090090/Come-Away-with-Me-With-Me-in-Seattle-1-by-Kristen-Proby.pdf
    • http://loaminoo.linkpc.net/3091091096099098/You-Know-You-Are-Pregnant-When-by-Kristen-Cummiskey.pdf
    • http://loaminoo.linkpc.net/3093094097097099/Motherest-by-Kristen-Iskandrian.pdf
    • http://loaminoo.linkpc.net/1091098095096096/Little-Arias-by-Kristen-Case.pdf
    • http://loaminoo.linkpc.net/3095092094091096/Three-Article-5-3-by-Kristen-Simmons.pdf
    • http://loaminoo.linkpc.net/4093090092098097/Law-Man-Dream-Man-3-by-Kristen-Ashley.pdf
    • http://loaminoo.linkpc.net/4097095098090097/Complicated-by-Kristen-Ashley.pdf
    • http://loaminoo.linkpc.net/1092095091094/The-Last-Warrior-by-Kristen-Kyle.pdf
    • http://loaminoo.linkpc.net/9090090098/Fall-VIP-3-by-Kristen-Callihan.pdf
    • http://loaminoo.linkpc.net/4096097097093099/Girls-Don-t-Fly-by-Kristen-Chandler.pdf
    • http://loaminoo.linkpc.net/8090094097094094/Classical-Lebanese-Cooking-Simple-Easy-and-Unique-Lebanese-Recipes-Lebanese-Recipes-Lebanese-Cookbook-Lebanese-Cooking-Leba