Malicious PDF — malware analysis report

Static analysis result for SHA-256 9754d468c8df7e40…

MALICIOUS

PDF

18.6 KB Created: 2019-04-30 18:39:17 +01:00 Authoring application: mPDF 5.7
MD5: f59b407112921c138d488774988ed14c SHA-1: cf228bc823fc41f916d28d42b6e106cea5bff0ae SHA-256: 9754d468c8df7e405a9af139367b83f1012afc4da63aefe94c7d8ae4852a83bd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the use of a dynamic DNS hostname suggest a link farm intended to manipulate search engine results or distribute potentially malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6095090098099095/The-Invaders-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/6098098097099098/The-Time-Machine-Winner-of-the-Cover-Design-Challenge-on-Work-of-Art-The-Next-Great-Artist-by-Bravo-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/4092098099091096/Retief-Ambassador-to-Space-Retief-5-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/3094095090090090/The-Great-Bird-Flu-Hoax-The-Truth-They-Don-t-Want-You-to-Know-About-the-Next-Big-Pandemic-by-Joseph-Mercola.pdf
    • http://loaminoo.linkpc.net/9098090095095092/Worlds-of-the-Imperium-Imperium-1-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/5090094093096090/Retief-of-the-CDT-Retief-7-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/4090096095090096/Imperium-Imperium-1-3-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/8091097091093092/The-Time-Machine-The-Original-Time-Travel-Story-A-Short-Science-Fiction-Novel-about-Time-Travel-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/3090097095095098/Bread-Lover-s-Bread-Machine-Cookbook-A-Master-Baker-s-300-Favorite-Recipes-for-Perfect-Every-Time-Bread-From-Every-Kind-of-Machine-by-Beth-Hensperger.pdf
    • http://loaminoo.linkpc.net/9091091094091091/The-Time-Machine-Centaur-Classics-The-100-greatest-novels-of-all-time---96-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/7090090097099090/The-Ultimate-Time-Machine-A-Remote-Viewer-s-Perception-of-Time-amp-Predictions-for-the-New-Millennium-by-Joseph-McMoneagle.pdf
    • http://loaminoo.linkpc.net/5097094091098092/The-Time-Machine-The-Original-Time-Travel-Story-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/9096098092096098/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/5093094097094094/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/1091095091096095097/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/3097097092098099/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/5096098090094091/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/2099099090096099/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/6092095099096099/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/4099091098093091/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/5090094093096090/Retief-of-the-CDT-Retief-7-by-K