Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d956ce2aff91dc1…

MALICIOUS

PDF

16.1 KB Created: 2019-05-02 05:13:15 +01:00 Authoring application: mPDF 5.7
MD5: d44e92279b126e4f2d62f69f37860d81 SHA-1: 3be95c0d071c58d56b7444056be5246f316c5694 SHA-256: 9d956ce2aff91dc155695fb5fd2f35bee7a2fd9873479e2f92b6d293bd64390a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a link farm, indicating a large number of embedded external links. The ML classifier also flagged the PDF as malicious with high confidence. While no scripts were extracted, the structure suggests a lure to download further malicious content from the listed URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095091096090095/Undeath-and-Taxes-Fred-the-Vampire-Accountant-2-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/2099094097096097/Undeath-and-Taxes-Fred-the-Vampire-Accountant-2-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/5092094095097097/Deadly-Assessments-Fred-the-Vampire-Accountant-5-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/3098097099090096/The-Fangs-of-Freelance-Fred-the-Vampire-Accountant-4-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/2094090090091099/Going-Rogue-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/4093093094099091/Pears-and-Perils-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/2099090096094092/Forging-Hephaestus-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/2097096092098098/Super-Powereds-Year-2-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/4094091094092090/Requiem-for-an-Elf-Poison-Elves-Vol-1-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/1093090092090095/NPCs-Spells-Swords-amp-Stealth-1-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/1091095094092091098/Corpies-Super-Powereds-Spinoff-1-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/4094093091090098/Dark-Wars-1-Poison-Elves-Volume-10-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/1090093096098091/The-Vampire-Fred-Wicked-Game-by-Vaughn-R-Demont.pdf
    • http://loaminoo.linkpc.net/2099094098091099/Super-Powereds-Year-4-Super-Powereds-4-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/2092092091099092/Super-Powereds-Year-3-Super-Powereds-3-by-Drew-Hayes.pdf
    • http://loaminoo.linkpc.net/3096092093094093/Hollywood-Days-with-Hayes-by-Hayes-Grier.pdf
    • http://loaminoo.linkpc.net/4099094098090095/Kiera-Hudson-Limited-Edition-Series-One-Vampire-Shift-Vampire-Wake-amp-Vampire-Hunt-Book-1-by-Tim-O-39-Rourke.pdf
    • http://loaminoo.linkpc.net/1090090099099090098/Corporate-Liquidations-for-the-Lawyer-and-Accountant-by-Howard-A-Rumpf.pdf
    • http://loaminoo.linkpc.net/7095093093091096/The-E-Myth-Accountant-Why-Most-Accounting-Practices-Don-t-Work-and-What-to-Do-about-It-by-Michael-E-Gerber.pdf
    • http://loaminoo.linkpc.net/1098099097095093/Gophers-Don-t-Pay-Taxes-by-Mervyn-J-Huston.pdf
    • http://loaminoo.linkpc.net/1090093096098091/The-Vampire-Fred-Wicked-G