Malicious PDF — malware analysis report

Static analysis result for SHA-256 9092a96265b8d8e3…

MALICIOUS

PDF

17.1 KB Created: 2019-05-02 17:11:37 +01:00 Authoring application: mPDF 5.7
MD5: 0fc8bc57b060385e65d584c1cbdb2fb2 SHA-1: 2c2afed7af5a6f2e0762363cbdb2bbd0f9130a9a SHA-256: 9092a96265b8d8e3bb7decbc47ee44ab9f43cedc96ea491c7afddbce036e2c5e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to act as a redirector to malicious sites. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkp
    • http://loaminoo.linkpc.net/9090098093096098/Marianne-and-the-Rebels-Marianne-5-by-Juliette-Benzoni.pdf
    • http://loaminoo.linkpc.net/2093091091094093/The-Marianne-Trilogy-Marianne-1-3-by-Sheri-S-Tepper.pdf
    • http://loaminoo.linkpc.net/6096090093099/A-Place-In-The-Woods-by-Helen-Hoover.pdf
    • http://loaminoo.linkpc.net/1091097093092092093/Marianne-Williamson-on-Death-Dying-by-Marianne-Williamson.pdf
    • http://loaminoo.linkpc.net/1091097093092092092/Marianne-Williamson-on-Hope-and-Happiness-by-Marianne-Williamson.pdf
    • http://loaminoo.linkpc.net/1091096097096099094/Seducing-Miss-Lockwood-by-Helen-Dickson.pdf
    • http://loaminoo.linkpc.net/1096098093091090/The-Dark-Volume-Miss-Temple-Doctor-Svenson-and-Cardinal-Chang-2-by-Gordon-Dahlquist.pdf
    • http://loaminoo.linkpc.net/3098098096096/The-Glass-Books-of-the-Dream-Eaters-Miss-Temple-Doctor-Svenson-and-Cardinal-Chang-1-by-Gordon-Dahlquist.pdf
    • http://loaminoo.linkpc.net/1090092090091099095/Faun-Lost-in-the-Woods-The-Faun-Woods-Book-1-by-Gen-Summercolt.pdf
    • http://loaminoo.linkpc.net/1091097093090099092/Marianne-Williamson-on-Simplicity-by-Marianne-Williamson.pdf
    • http://loaminoo.linkpc.net/9090098096094092/Marianne-Williamson-on-Success-by-Marianne-Williamson.pdf
    • http://loaminoo.linkpc.net/1091097093090098097/Marianne-Williamson-on-Communication-by-Marianne-Williamson.pdf
    • http://loaminoo.linkpc.net/9090098095091093/Marianne-Williamson-on-Self-Esteem-by-Marianne-Williamson.pdf
    • http://loaminoo.linkpc.net/9090098095091092/Marianne-Williamson-On-Miracles-by-Marianne-Williamson.pdf
    • http://loaminoo.linkpc.net/1091097093090099093/Marianne-Williamson-On-Commitment-by-Marianne-Williamson.pdf
    • http://loaminoo.linkpc.net/3098099090091099/Saving-Miss-Oliver-s-Miss-Oliver-s-School-for-Girls-1-by-Stephen-Davenport.pdf
    • http://loaminoo.linkpc.net/2092095092099091/Miss-Peregrine-s-Home-for-Peculiar-Children-Miss-Peregrine-1-by-Ransom-Riggs.pdf
    • http://loaminoo.linkpc.net/2099090093094091/Miss-Marple-The-Complete-Short-Stories-Miss-Marple-15-by-Agatha-Christie.pdf
    • http://loaminoo.linkpc.net/3096093099093099/The-Glass-Books-of-the-Dream-Eaters-Volume-Two-Miss-Temple-Doctor-Svenson-and-Cardinal-Chang-1-2-by-Gordon-Dahlquist.pdf
    • http://loaminoo.linkpc.net/1094091099096095/Miss-Popularity-Miss-Popularity-1-Candy-Apple-3-by-Francesco-Sedita.pdf