Malicious PDF — malware analysis report

Static analysis result for SHA-256 86311c4d853e415a…

MALICIOUS

PDF

17.9 KB Created: 2019-04-29 23:15:45 +01:00 Authoring application: mPDF 5.7
MD5: 215d93294aa0fee118ae255fd7ca0416 SHA-1: b55313dc2fd3b52e0e05dfeaedbc8f51e8379cad SHA-256: 86311c4d853e415a00f1ed565ad4a690c522e13d7e47abc45c4396eec94753a4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains a large number of embedded URLs, identified as a link farm. While the document body is heavily obfuscated, the presence of numerous links to external resources suggests a malicious intent, possibly for SEO manipulation or to redirect users to malicious sites. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099091098097092/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/2090092094092097/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/1097095098096099/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/1090092095095/The-Storied-Life-of-A-J-Fikry-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/6099098099098097/Summary-of-The-Storied-Life-of-A-J-Fikry-A-Novel-by-Gabrielle-Zevin-Trivia-Quiz-for-Fans-by-Whiz-Books.pdf
    • http://loaminoo.linkpc.net/6099098099096091/The-Storied-Life-of-A-J-Fikry-A-Novel-by-Gabrielle-Zevin-Trivia-on-Books-by-Trivion-Books.pdf
    • http://loaminoo.linkpc.net/3095092095092090/The-Hole-We-re-in-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/1092096097095095/Because-It-Is-My-Blood-Birthright-2-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/2098095094094093/All-These-Things-I-ve-Done-Birthright-1-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/6099098099095098/Script-Conversations-with-Other-Women-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/2098090090092094/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/1097095099097098/Memoirs-of-a-Teenage-Amnesiac-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/6091097098/Young-Jane-Young-by-Gabrielle-Zevin.pdf
    • http://loaminoo.linkpc.net/2092097099095092/Dan-Gets-a-Minivan-Life-at-the-Intersection-of-Dude-and-Dad-by-Dan-Zevin.pdf
    • http://loaminoo.linkpc.net/6099098097095090/Entry-Level-Life-A-Complete-Guide-to-Masquerading-as-a-Member-of-the-Real-World-by-Dan-Zevin.pdf
    • http://loaminoo.linkpc.net/4094098095098091/Snowball-Earth-The-Story-of-the-Great-Global-Catastrophe-That-Spawned-Life-as-We-Know-It-by-Gabrielle-Walker.pdf
    • http://loaminoo.linkpc.net/4094099092096093/Miracles-Now-108-Life-Changing-Tools-for-Less-Stress-More-Flow-and-Finding-Your-True-Purpose-by-Gabrielle-Bernstein.pdf
    • http://loaminoo.linkpc.net/4099095091096/Oregon-This-Storied-Land-by-William-G-Robbins.pdf
    • http://loaminoo.linkpc.net/6093099097093096/Toile-The-Storied-Fabrics-of-Europe-and-America-by-Michele-Palmer.pdf
    • http://loaminoo.linkpc.net/6099098099095097/The-Nearly-Wed-Handbook-by-Dan-Zevin.pdf