Malicious PDF — malware analysis report

Static analysis result for SHA-256 9279b74c1ef30e4a…

MALICIOUS

PDF

20.8 KB Created: 2019-05-02 02:43:36 +01:00 Authoring application: mPDF 5.7
MD5: 2257fafda2fb0b788f9c0ee96c6c7f0e SHA-1: 55dade61eef2411e86f672af924e22878f6f42df SHA-256: 9279b74c1ef30e4a838bdb4351f4644781fc33c595cdea841b1ae6b906d4dc66
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm used for SEO manipulation or to redirect users to malicious sites. While no scripts were extracted, the sheer volume of links and the ML classification strongly suggest a malicious intent to lure users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099091093099099/Nine-Dragons-Harry-Bosch-15-Harry-Bosch-Universe-20-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/3093093097099099/Dark-Sacred-Night-Ren-e-Ballard-2-Harry-Bosch-21-Harry-Bosch-Universe-31-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/5093092090099/A-Darkness-More-Than-Night-Harry-Bosch-7-Terry-McCaleb-2-Harry-Bosch-Universe-9-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/3098091094092091/The-Wrong-Side-of-Goodbye-Harry-Bosch-19-Harry-Bosch-Universe-28-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/4096097095092097/The-Reversal-Harry-Bosch-16-Mickey-Haller-3-Harry-Bosch-Universe-21-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/4093098097/The-Wrong-Side-of-Goodbye-Harry-Bosch-19-Harry-Bosch-Universe-28-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/4099090092092093/Angels-Flight-Harry-Bosch-6-Harry-Bosch-Universe-7-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/4091095094098/Lost-Light-Harry-Bosch-9-Harry-Bosch-Universe-11-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/4099092099090094/Angle-of-Investigation-Harry-Bosch-14-7-Harry-Bosch-Universe-22-2-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/2091097096096093/The-Black-Echo-Harry-Bosch-1-Harry-Bosch-Universe-1-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/2097091097095/The-Concrete-Blonde-Harry-Bosch-3-Harry-Bosch-Universe-3-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/1093091095096091/The-Black-Box-Harry-Bosch-16-Harry-Bosch-Universe-24-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/8090096094098/The-Narrows-Harry-Bosch-10-Harry-Bosch-Universe-13-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/7097092091096/The-Overlook-Harry-Bosch-13-Harry-Bosch-Universe-17-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/3098091093090099/Switchblade-Harry-Bosch-16-5-Harry-Bosch-Universe-25-5-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/1093098094095091/The-Last-Coyote-Harry-Bosch-4-Harry-Bosch-Universe-4-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/3098095099099099/The-Harry-Bosch-Mysteries-Volume-2-The-Last-Coyote-Trunk-Music-Angels-Flight-Harry-Bosch-4-6-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/2091093095097095/The-Harry-Bosch-Novels-Volume-1-The-Black-Echo-The-Black-Ice-The-Concrete-Blonde-Harry-Bosch-1-3-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/4096097096095098/The-Fifth-Witness-Mickey-Haller-4-Harry-Bosch-Universe-22-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/2096098098094/The-Poet-Jack-McEvoy-1-Harry-Bosch-Universe-5-by-Michael-Connelly.pdf
    • http://loaminoo.linkpc.net/40930