Malicious PDF — malware analysis report

Static analysis result for SHA-256 88819b2d6ec41718…

MALICIOUS

PDF

16.5 KB Created: 2019-05-01 12:45:22 +01:00 Authoring application: mPDF 5.7
MD5: a14f8d7c4a0e754c8e77b0b736ce00a7 SHA-1: 565cf3a79929de7cb5022bc01cab6f07f04c4277 SHA-256: 88819b2d6ec41718b2d7276eca82cba8c54ae1f83f7db37148686a8f5c4c81b6
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external sites. ClamAV detection as Pdf.Dropper.Agent-7375785-0 and the ML classifier output further support its malicious nature. The primary function appears to be directing users to a link farm, likely for SEO spam or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7375785-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7375785-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3092099096098093/HOT-SEAL-Bride-HOT-SEAL-Team-4-by-Lynn-Raye-Harris.pdf
    • http://loaminoo.linkpc.net/3099095091096099/HOT-SEAL-Rescue-HOT-SEAL-Team-3-by-Lynn-Raye-Harris.pdf
    • http://loaminoo.linkpc.net/3099090096091091/Hot-SEAL-HOT-SEAL-Team-1-by-Lynn-Raye-Harris.pdf
    • http://loaminoo.linkpc.net/3099095097098094/Hot-Ice-Hostile-Operations-Team-7-by-Lynn-Raye-Harris.pdf
    • http://loaminoo.linkpc.net/3099095091098096/Hot-Addiction-Hostile-Operations-Team-10-by-Lynn-Raye-Harris.pdf
    • http://loaminoo.linkpc.net/4098096091096098/Hot-Witness-Hostile-Operations-Team-9-5-The-MacKenzie-Family-12-2-by-Lynn-Raye-Harris.pdf
    • http://loaminoo.linkpc.net/6094098098097093/A-Hostile-Operations-Team-Boxed-Set-Volume-1-Hostile-Operations-Team-1-3-by-Lynn-Raye-Harris.pdf
    • http://loaminoo.linkpc.net/4091098091091094/Cowboy-SEAL-Christmas-Navy-SEAL-Cowboys-3-by-Nicole-Helm.pdf
    • http://loaminoo.linkpc.net/3093096099099099/Romancing-the-SEAL-The-Call-of-Duty-Book-1-SEAL-Military-Romance-Series-by-Abigail-Austin.pdf
    • http://loaminoo.linkpc.net/3093097090096098/Romancing-the-SEAL-Hero-s-Honor-Book-2-SEAL-Military-Romance-Series-by-Abigail-Austin.pdf
    • http://loaminoo.linkpc.net/4095098095097096/Accidental-SEAL-SEAL-Brotherhood-1-by-Sharon-Hamilton.pdf
    • http://loaminoo.linkpc.net/4097095096094094/SEAL-Under-Covers-SEAL-Brotherhood-3-by-Sharon-Hamilton.pdf
    • http://loaminoo.linkpc.net/4093095099092097/Seal-Team-666-by-Weston-Ochse.pdf
    • http://loaminoo.linkpc.net/2099094098093/SEAL-Team-Six-by-Howard-E-Wasdin.pdf
    • http://loaminoo.linkpc.net/2097097091095091/SEAL-Team-13-by-Evan-Currie.pdf
    • http://loaminoo.linkpc.net/3091094095093097/Don-t-Let-Go-SEAL-Team-12-5-by-Marliss-Melton.pdf
    • http://loaminoo.linkpc.net/2094091093097096/Seal-Team-One-by-Dick-Couch.pdf
    • http://loaminoo.linkpc.net/3090096090097096/In-the-Dark-SEAL-Team-12-2-by-Marliss-Melton.pdf
    • http://loaminoo.linkpc.net/1094090096091098/Time-to-Run-SEAL-Team-12-3-by-Marliss-Melton.pdf
    • http://loaminoo.linkpc.net/1094098091097093/Show-No-Fear-SEAL-Team-12-7-by-Marliss-Melton.pdf
    • http://loaminoo.linkpc.net/409109809109