Malicious PDF — malware analysis report

Static analysis result for SHA-256 87bbe2a0a71e734b…

MALICIOUS

PDF

19.7 KB Created: 2019-05-02 03:29:34 +01:00 Authoring application: mPDF 5.7
MD5: cf21af3df1af2e214f43b617b5575823 SHA-1: 76279bb1c2af5ffc4080bacec9efc94e97ae9189 SHA-256: 87bbe2a0a71e734baa7d539261a11af76ca4d30614654a6a28e4e365754ad46e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. While the URLs themselves are currently marked as benign, the overall pattern suggests an attempt to drive traffic or distribute further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1094091092093096/Road-from-Ar-Ramadi-The-Private-Rebellion-of-Sergeant-Camilo-Mejia-by-Camilo-Mejia.pdf
    • http://loaminoo.linkpc.net/4091096099095092/Sunrises-to-Santiago-Searching-for-Purpose-on-the-Camino-de-Santiago-by-Gabriel-Schirm.pdf
    • http://loaminoo.linkpc.net/5090094096092090/Everything-You-Want-Me-to-Be-A-Novel-by-Mindy-Mejia.pdf
    • http://loaminoo.linkpc.net/1096098098090091/Palace-of-Lies-The-Palace-Chronicles-3-by-Margaret-Peterson-Haddix.pdf
    • http://loaminoo.linkpc.net/1092091090092091/Palace-of-the-Three-Crosses-Palace-of-the-Twelve-Pillars-2-by-Christina-Weigand.pdf
    • http://loaminoo.linkpc.net/9091091097096092/Palace-of-Glass---Die-W-chterin-Palace-Saga-1-by-C-E-Bernard.pdf
    • http://loaminoo.linkpc.net/1090098099096093090/Palast-Im-Vereinigten-Konigreich-Palast-in-London-Tower-of-London-Palace-of-Westminster-Buckingham-Palace-Bruce-Castle-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/3097095095098/The-Cairo-Trilogy-Palace-Walk-Palace-of-Desire-Sugar-Street-The-Cairo-Trilogy-1-3-by-Naguib-Mahfouz.pdf
    • http://loaminoo.linkpc.net/6094096095098097/A-New-Guide-to-the-Museum-Palace-and-Gardens-of-Versailles-Being-an-Exact-Description-Drawn-Up-by-Galleries-Apartments-and-Numbers-of-the-Paintings-Portraits-and-Sculptures-of-the-Palace-Its-Yards-and-Gardens-by-Versailles-Versailles.pdf
    • http://loaminoo.linkpc.net/4094090090094098/Zingy-by-Paola-Opal.pdf
    • http://loaminoo.linkpc.net/7096093097095092/Bardo-by-Suzanne-Paola.pdf
    • http://loaminoo.linkpc.net/5092093098097093/Crooked-Trees-by-Folco-Paola.pdf
    • http://loaminoo.linkpc.net/4096095099090098/The-Power-of-Courage-W-I-T-C-H-46-by-Paola-Mulazzi.pdf
    • http://loaminoo.linkpc.net/6091095093091092/The-Leipzig-Connection-by-Paola-Lionni.pdf
    • http://loaminoo.linkpc.net/1090099097098090090/La-Citta-Elementare-by-Paola-Vigano.pdf
    • http://loaminoo.linkpc.net/1090095099097094098/Giovanna-s-86-Circles-And-Other-Stories-by-Paola-Corso.pdf
    • http://loaminoo.linkpc.net/1092094090091098/Palace-of-Spies-Palace-of-Spies-1-by-Sarah-Zettel.pdf
    • http://loaminoo.linkpc.net/4090097091098098/Gilles-Deleuze-Cinema-and-Philosophy-by-Paola-Marrati.pdf
    • http://loaminoo.linkpc.net/1090096090090094092/Italienisch-in-30-Tagen-Der-kompakte-Sprachkurs-by-Paola-Frattola-Roberta-Costantino.pdf
    • http://loaminoo.linkpc.net/2090099094090092/We-The-Drowned-by-Carsten-Jensen.pdf