Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a2772956445618b…

MALICIOUS

PDF

15.5 KB Created: 2019-04-30 15:49:05 +01:00 Authoring application: mPDF 5.7
MD5: faca6f0fdb99602987d1dcdf59eb61c0 SHA-1: 30a6e0253eb5b47ca995c8d93c2da23e762d280d SHA-256: 9a2772956445618b87c9456ffa6dd64d639f28bcd75f295a3ce163cdee3ccdff
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a link farm or SEO spamming operation. The ML_NYX_PDF_MALICIOUS classifier also flagged the document with high confidence. While no scripts were extracted, the sheer volume of links points to a malicious intent to redirect users to potentially harmful content or to manipulate search engine rankings. The document body was unreadable, preventing further analysis of its specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3090098099098093/The-Able-Life-of-Cody-Jane-Still-Celebrating-by-Marly-Cornell.pdf
    • http://loaminoo.linkpc.net/4094092095090091/On-Women-Turning-50-Celebrating-Mid-Life-Discoveries-by-Cathleen-Rountree.pdf
    • http://loaminoo.linkpc.net/3098091093098098/Shelf-Life-Fantastic-Stories-Celebrating-Bookstores-by-Greg-Ketter.pdf
    • http://loaminoo.linkpc.net/3096091090099090/Fantastic-Illusions-of-Life-Love-the-Birds-and-the-Bees-by-Jenna-Cornell.pdf
    • http://loaminoo.linkpc.net/8096098097090092/The-Life-amp-Death-Of-Cody-Parker-Tanner-5-by-Remington-Kane.pdf
    • http://loaminoo.linkpc.net/1097099095099098/Thaliad-by-Marly-Youmans.pdf
    • http://loaminoo.linkpc.net/2095095096097098/The-Wolf-Pit-by-Marly-Youmans.pdf
    • http://loaminoo.linkpc.net/6097099098099/Evening-News-by-Marly-Swick.pdf
    • http://loaminoo.linkpc.net/4097091092093098/Dark-Phoenix-by-Marly-Mathews.pdf
    • http://loaminoo.linkpc.net/4097098091096096/Marly-s-Choice-Men-of-August-1-by-Lora-Leigh.pdf
    • http://loaminoo.linkpc.net/1090090094093091098/Let-s-Go-Map-Guide-Seattle-Newly-Revised-by-Marly-Ohlsson.pdf
    • http://loaminoo.linkpc.net/7093098092095093/A-Death-at-the-White-Camellia-Orphanage-by-Marly-Youmans.pdf
    • http://loaminoo.linkpc.net/6097091093099098/Palaces-of-the-Sun-King-Versailles-Trianon-Marly--The-Chateaux-of-Louis-XIV-by-Vicomte-de-Rohan.pdf
    • http://loaminoo.linkpc.net/1094093092090098/Jane-Austen-A-Life-by-Carol-Shields.pdf
    • http://loaminoo.linkpc.net/8097091094099091/Antonia-White-a-Life-by-Jane-Dunn.pdf
    • http://loaminoo.linkpc.net/1090099092096093099/In-the-Blink-of-an-Eye-My-Life-with-RSDS-by-Mary-Jane-Gonzales.pdf
    • http://loaminoo.linkpc.net/8091099098090/Eyes-on-the-Street-The-Life-of-Jane-Jacobs-by-Robert-Kanigel.pdf
    • http://loaminoo.linkpc.net/1099093093093/Jane-Crow-The-Life-of-Pauli-Murray-by-Rosalind-Rosenberg.pdf
    • http://loaminoo.linkpc.net/4092093090094090/Remarkable-Changes-Turning-Life-s-Challenges-into-Opportunities-by-Jane-Seymour.pdf
    • http://loaminoo.linkpc.net/4093097096092092/The-Watcher-Jane-Goodall-s-Life-with-the-Chimps-by-Jeanette-Winter.pdf
    • http://loaminoo.linkpc.net/409709