Malicious PDF — malware analysis report

Static analysis result for SHA-256 928e06450ee44a2c…

MALICIOUS

PDF

18.7 KB Created: 2019-04-30 04:48:51 +01:00 Authoring application: mPDF 5.7
MD5: dae0e3e41daa26399c93abe391166de9 SHA-1: ea086776d18cb450029e9b06d60e1b4ca37474ed SHA-256: 928e06450ee44a2cebb6dead44415bb3da74cfae947b42b2c56e352e5eeae7af
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external resources, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to manipulate search engine results or redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5098095097092094/100-Ideas-that-Changed-Photography-by-Mary-Warner-Marien.pdf
    • http://loaminoo.linkpc.net/9096090098092090/Film-Critics-Richard-Fitzwilliams-Benjamin-Urrutia-Uwe-Nettelbeck-Siegfried-Kracauer-Robin-Wood-Joko-Anwar-List-of-Film-Critics-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/1091097094095092/Alone-of-All-Her-Sex-The-Myth-and-the-Cult-of-the-Virgin-Mary-by-Marina-Warner.pdf
    • http://loaminoo.linkpc.net/1090095095096097097/Picturing-the-Maghreb-Literature-Photography-Representation-by-Mary-B-Vogl.pdf
    • http://loaminoo.linkpc.net/6099093093091093/Hollywood-Be-Thy-Name-The-Warner-Brothers-Story-by-Cass-Warner-Sperling.pdf
    • http://loaminoo.linkpc.net/6095095090098099/Photography-Photography-Lighting-Hacks-7-Must-Know-Lighting-Tips-For-Dramatically-Stunning-Photos-Every-Time-by-Eric-Adamo.pdf
    • http://loaminoo.linkpc.net/7093090099092/The-Element-of-Lavishness-Letters-of-William-Maxwell-and-Sylvia-Townsend-Warner-1938-1978-by-Sylvia-Townsend-Warner.pdf
    • http://loaminoo.linkpc.net/6090090092099092/Joie-Warner-s-No-Cook-Pasta-Sauces-by-Joie-Warner.pdf
    • http://loaminoo.linkpc.net/5098095099090090/The-Age-of-the-AKP-by-Mari-n-Dur-n.pdf
    • http://loaminoo.linkpc.net/5098095097093098/Cada-vez-que-no-me-miras-by-Marien-Koan.pdf
    • http://loaminoo.linkpc.net/1093097091099099/Killing-Critics-Kathleen-Mallory-3-by-Carol-O-39-Connell.pdf
    • http://loaminoo.linkpc.net/9099095094090097/Constable-And-The-Critics-1802-1837-by-Judy-Crosby-Ivy.pdf
    • http://loaminoo.linkpc.net/5093091096097096/Du-temps-qu-on-existait---Prix-de-Flore-by-Marien-Defalvard.pdf
    • http://loaminoo.linkpc.net/5098095097096096/La-Novela-Que-Marien-No-Termin-o-by-Carmen-G-mez-Ojea.pdf
    • http://loaminoo.linkpc.net/3098092092091095/Taking-Rights-Seriously-With-a-New-Appendix-a-Response-to-Critics-by-Ronald-Dworkin.pdf
    • http://loaminoo.linkpc.net/2091098092092/The-Critics-Bear-it-Away-American-Fiction-and-the-Academy-by-Frederick-C-Crews.pdf
    • http://loaminoo.linkpc.net/4098090099090092/Theories-of-Modern-Art-A-Source-Book-by-Artists-and-Critics-by-Herschel-B-Chipp.pdf
    • http://loaminoo.linkpc.net/1091094099098092098/Yorick-And-The-Critics-Sterne-s-Reputation-In-England-1760-1868-by-Alan-B-Howes.pdf
    • http://loaminoo.linkpc.net/5098095098099099/Practice-Using-Lotus-1-2-3-Active-Learning-Made-Easy-with-by-Deryk-Marien.pdf
    • http://loaminoo.linkpc.net/5098095097093092/Minor-Aesthetics-The-Photographic-Work-of-Marcel-Marien-by-Mieke-Bleyen.pdf
    • http://loaminoo.linkpc.net/6095095090098099/Photography-Photography-Lighting-Hacks-7-Must-Know-Lighting-Tips-For-Dramatically-Stunning-Photos-Every-T