Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2a2d959cc15e82c…

MALICIOUS

PDF

22.1 KB Created: 2019-05-05 13:50:20 +01:00 Authoring application: mPDF 5.7
MD5: 2dbc8cb1ab8e68479497adec727dcd70 SHA-1: e69776fcbfbc70162fd492eb398405f234fe1e6a SHA-256: a2a2d959cc15e82c17ec900320a209b32d913c8d3e6b5e900c446905d4098122
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092095093095092/Ghosts-Don-t-Eat-Potato-Chips-The-Adventures-of-the-Bailey-School-Kids-5-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/4097094093092093/Angels-Don-t-Know-Karate-The-Adventures-Of-The-Bailey-School-Kids-23-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/1098090099092093/Gremlins-Don-t-Chew-Bubble-Gum-Adventures-Of-The-Bailey-School-Kids-13-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/4090096095092099/Zombies-Don-t-Play-Soccer-The-Adventures-of-the-Bailey-School-Kids-15-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/2094091091099097/Cupid-Doesn-t-Flip-Hamburgers-The-Adventures-of-the-Bailey-School-Kids-12-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/1091099090091095093/Santa-Claus-Doesn-t-Mop-Floors-The-Adventures-of-the-Bailey-School-Kids-3-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/6097095099097098/Frankenstein-Doesn-t-Plant-Petunias-The-Adventures-Of-The-Bailey-School-Kids-6-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/2098099097090098/Elves-Don-t-Wear-Hard-Hats-The-Adventures-of-the-Bailey-School-Kids-17-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/2098097091093097/Frankenstein-Doesn-t-Slam-Hockey-Pucks-The-Adventures-of-the-Bailey-School-Kids-34-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/5097095091093091/Rhinoceroses-amp-Potato-Chips-by-M-E-Wonder.pdf
    • http://loaminoo.linkpc.net/6093093096097095/The-Polar-Bear-Express-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/3090093093097092/Trouble-at-Trident-Academy-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/4099090097094099/Charms-and-Chocolate-Chips-A-Magical-Bakery-Mystery-3-by-Bailey-Cates.pdf
    • http://loaminoo.linkpc.net/3091093096096093/MAGICAL-ASSORTMENT-OF-SHORT-KIDS-STORIES-14-Stories-in-1-KIDS-BOOK-PICTURES-BOOK-CHILDREN-S-BOOK-PRE-SCHOOL-FAIRLY-TALE-EARLY-LEARNING-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091092097093091/Ghosts-Who-Went-to-School-by-Judith-Spearing.pdf
    • http://loaminoo.linkpc.net/3098095097091096/The-Cooper-Kids-The-Cooper-Kids-Adventures-1-4-by-Frank-E-Peretti.pdf
    • http://loaminoo.linkpc.net/1099096090099090/One-Potato-Two-Potato-by-Cynthia-C-DeFelice.pdf
    • http://loaminoo.linkpc.net/6096094091097093/Alice-s-Adventures-In-Wonderland-amp-Through-The-Looking-Glass-by-Debbie-Guthery.pdf
    • http://loaminoo.linkpc.net/2097099092095097/Why-Kids-Kill-Inside-the-Minds-of-School-Shooters-by-Peter-Langman.pdf
    • http://loaminoo.linkpc.net/1090099093093090096/Sweet-Potato-Recipes-Top-37-Easy-Quick-Healthy-amp-Delicious-Sweet-Potato-Recipes-by-Jamie-Fynn.pdf
    • http://loaminoo.linkpc.net/6097095099097098/Frankenstein-Doesn-t-Plant-Petunias-The-Adventures-Of-The-Bailey-School-Kids-6-by-Debbi