Malicious PDF — malware analysis report

Static analysis result for SHA-256 8df2ab30bcf0e82b…

MALICIOUS

PDF

14.8 KB Created: 2019-04-30 02:57:02 +01:00 Authoring application: mPDF 5.7
MD5: 11c1df28094c87bf995843101334224b SHA-1: 4c01eab68dfb698badd62fa7a761526c81540ecc SHA-256: 8df2ab30bcf0e82bf491f1c3ae9416b8964433b8562c7a88d0419f595d6005bd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. While the URLs themselves are currently marked as benign, the heuristic 'PDF_SEO_LINK_FARM' indicates a pattern often used for SEO manipulation or to host malicious content. No scripts were extracted from this sample. The primary attack pattern appears to be the distribution of a large number of links, potentially to distribute malware or engage in phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4093096092090094/The-Rule-of-Nine-Paul-Madriani-11-by-Steve-Martini.pdf
    • http://loaminoo.linkpc.net/9097093099092099/The-Arraignment-Paul-Madriani-7-by-Steve-Martini.pdf
    • http://loaminoo.linkpc.net/9097093098098093/Shadow-of-Power-Paul-Madriani-9-by-Steve-Martini.pdf
    • http://loaminoo.linkpc.net/3094098091097092/The-Enemy-Inside-Paul-Madriani-13-by-Steve-Martini.pdf
    • http://loaminoo.linkpc.net/5096098091094092/Guardian-of-Lies-Paul-Madriani-10-by-Steve-Martini.pdf
    • http://loaminoo.linkpc.net/9097093099093090/Blood-Flag-Paul-Madriani-14-by-Steve-Martini.pdf
    • http://loaminoo.linkpc.net/1090091099090099091/The-Jury-by-Steve-Martini.pdf
    • http://loaminoo.linkpc.net/1092092096096094/The-Simeon-Chamber-by-Steve-Martini.pdf
    • http://loaminoo.linkpc.net/1098091094091/Musichound-Lounge-The-Essential-Album-Guide-to-Martini-Music-and-Easy-Listening-by-Steve-Knopper.pdf
    • http://loaminoo.linkpc.net/3096098098091097/The-First-Rule-of-Survival-Col-Vaughn-de-Vries-1-by-Paul-Mendelson.pdf
    • http://loaminoo.linkpc.net/4095095090091098/Rule-s-Addiction-The-House-of-Rule-3-by-Lynda-Chance.pdf
    • http://loaminoo.linkpc.net/1092098095097090/Twenty-One-Year-Rule-The-Rule-3-by-Alaina-Stanford.pdf
    • http://loaminoo.linkpc.net/3092099096/The-Rule-Book-The-Rule-Breakers-1-by-Jennifer-Blackwood.pdf
    • http://loaminoo.linkpc.net/9097096090097097/Steve-Cotter---The-Complete-Guide-to-Kettlebell-Lifting-by-Paul-F-Viele.pdf
    • http://loaminoo.linkpc.net/8098092094/Rule-Rule-1-by-Ellen-Goodlett.pdf
    • http://loaminoo.linkpc.net/3096097096096094/The-New-Rule-The-Casual-Rule-2-by-A-C-Netzel.pdf
    • http://loaminoo.linkpc.net/4091094097091091/Vampires-Rule-Rule-1-by-K-C-Blake.pdf
    • http://loaminoo.linkpc.net/9097093099094099/Martini-Seduction-by-Christa-Tomlinson.pdf
    • http://loaminoo.linkpc.net/9097093099093095/Martini-Book-by-Sally-Ann-Berk.pdf
    • http://loaminoo.linkpc.net/2096096099093096/Shaken-The-Martini-Sisterhood-1-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/3096098098091097/The-First-Rule-of-Survival-Col-Vaughn-de-Vries-1-by-Paul-Mendelson.pd