Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c2b8257dc14d5e0…

MALICIOUS

PDF

22.7 KB Created: 2019-04-30 05:52:26 +01:00 Authoring application: mPDF 5.7
MD5: e4f94a3e296a47ad2e5b86f79fe243a3 SHA-1: 5e59841337c48ba1afb0cfeea75eb62859bf5614 SHA-256: 8c2b8257dc14d5e02a8c45f230fb97452bb7340698b3d486eca77052333039af
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. While no scripts were extracted, the sheer volume of links points to a malicious intent, likely to manipulate search engine results or redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2091091093093095/Sorority-Pledge-Collection-Steamy-Books-1-5-by-Daizie-Draper.pdf
    • http://loaminoo.linkpc.net/2091091094096096/Sorority-Pledge-1-A-Devil-in-Disguise-by-Daizie-Draper.pdf
    • http://loaminoo.linkpc.net/4094096091095099/Sorority-Pledge-3-Bad-Girl-on-the-Rise-by-Daizie-Draper.pdf
    • http://loaminoo.linkpc.net/4095098096/Naughty-Boss-Steamy-Coffee-Collection-1-by-Whitney-G-.pdf
    • http://loaminoo.linkpc.net/9096099094096098/Erotica-Stepbrother-s-Taboo-Desire-Steamy-Stories-A-BBW-Threesome-Menage-Story-Collection-A-Billionaire-Stepbrother-Taboo-MMF-New-Adult-Hot-Romance-Collection-Series-by-Mindreader-Desires.pdf
    • http://loaminoo.linkpc.net/2091097099095099/The-Sorority-Sorority-Trilogy-1-3-by-Tamara-Thorne.pdf
    • http://loaminoo.linkpc.net/3099099091097092/The-Pledge-The-Pledge-1-by-Kimberly-Derting.pdf
    • http://loaminoo.linkpc.net/3091093093090090/Children-s-Adventure-Story-Bundle-5-4-Books-in-1-Kids-Bedtime-Stories-Collection-Books-about-music-life-animals-planets-Family-Coming-of-age-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/2095094091092095/Children-books-SOPHIE-S-SURPRISE-EGG-Beginner-readers-early-readers-amp-learning-kids-collection-Fiction-story-picture-books-for-children-amp-Toddlers-Bedtime-fiction-beginner-reader-books-Book-2-by-Alex-Man.pdf
    • http://loaminoo.linkpc.net/1090099095095096096/Children-books-The-Book-of-Feelings-Friendship-Values-book-Adventure-amp-Education-Kids-books-Emotions-Feelings-Growing-up-amp-facts-of-life-Social-skills-for-kids-collection-by-Lilach-Yitzhaki.pdf
    • http://loaminoo.linkpc.net/8090092090097092/The-Brimshire-Collection-Books-1-10-by-R-R-Bisso.pdf
    • http://loaminoo.linkpc.net/8095099095096/The-In-Death-Collection-Books-1-5-by-J-D-Robb.pdf
    • http://loaminoo.linkpc.net/7097094095098092/Hobbes-Unhuman-Collection-Books-I-IV-by-Wilkie-Martin.pdf
    • http://loaminoo.linkpc.net/4091092097098097/The-Walsh-Collection-Books-3-amp-4-The-Walshes-3-4-by-Kate-Canterbary.pdf
    • http://loaminoo.linkpc.net/8090098096095094/Agatha-Raisin-Series-Collection-10-Books-Set-by-M-C-Beaton.pdf
    • http://loaminoo.linkpc.net/1091097092091090094/Septimus-Heap-7-Books-Collection-Set-by-Angie-Sage.pdf
    • http://loaminoo.linkpc.net/2099095094090099/The-Dragon-Blood-Collection-Books-1-3-by-Lindsay-Buroker.pdf
    • http://loaminoo.linkpc.net/5097097091096093/Lord-of-the-Flies-2-Books-Bundle-Collection-by-William-Golding.pdf
    • http://loaminoo.linkpc.net/4091095093099098/The-Beam-The-Complete-Second-Season-Collection-Books-7-12-by-Sean-Platt.pdf
    • http://loaminoo.linkpc.net/1090092097092091091/Marvin-Redpost-Complete-Collection-8-books-by-Louis-Sachar.pdf