Malicious PDF — malware analysis report

Static analysis result for SHA-256 a43b6cac4c21d2af…

MALICIOUS

PDF

17.3 KB Created: 2019-04-30 08:29:01 +01:00 Authoring application: mPDF 5.7
MD5: c87e1830d6db19809867de8f7db0367f SHA-1: 92231801d693217f86f17b974dd6ef48702b57c7 SHA-256: a43b6cac4c21d2afdf3fa57f73575b29228053d6b495615b7c03bb2ecb5ae376
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign-looking poetry PDFs hosted on loaminoo.linkpc.net, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to harmful content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091094097090093/Gulf-Music-Poems-by-Robert-Pinsky.pdf
    • http://loaminoo.linkpc.net/4094096098093096/Poetry-of-the-Universe-by-Robert-Osserman.pdf
    • http://loaminoo.linkpc.net/8099099095097096/Mythmaking-The-Mythological-Poetry-of-Robert-Desnos-by-Robert-Desnos.pdf
    • http://loaminoo.linkpc.net/6090099091090093/The-Poetry-of-Rimbaud-by-Robert-Greer-Cohn.pdf
    • http://loaminoo.linkpc.net/9090093099093099/The-Best-American-Poetry-2001-by-Robert-Hass.pdf
    • http://loaminoo.linkpc.net/1099094092098096/The-Penguin-Book-of-First-World-War-Poetry-by-Jon-Silkin.pdf
    • http://loaminoo.linkpc.net/5096092094093093/At-an-Elevation-On-the-Poetry-of-Robert-Pack-by-David-Haward-Bain.pdf
    • http://loaminoo.linkpc.net/2091093094091/Twentieth-Century-Pleasures-Prose-on-Poetry-by-Robert-Hass.pdf
    • http://loaminoo.linkpc.net/4095097099099096/Belonging-New-Poetry-by-Iranians-Around-the-World-by-Niloufar-Talebi.pdf
    • http://loaminoo.linkpc.net/9098098092094099/The-Discourse-of-Nature-in-the-Poetry-of-Paul-Celan-The-Unnatural-World-by-Rochelle-Tobias.pdf
    • http://loaminoo.linkpc.net/2092092091098090/Georgian-Poetry-Poems-by-D-H-Lawrence-Siegfried-Sassoon-Rupert-Brooke-Robert-Graves-Edmund-Blunden-Walter-de-la-Mare-amp-Others-by-Keith-Hale.pdf
    • http://loaminoo.linkpc.net/1091096099099090/Eyes-of-the-God-The-Weird-Fiction-and-Poetry-of-R-H-Barlow-by-Robert-H-Barlow.pdf
    • http://loaminoo.linkpc.net/6096093094092098/Poetry-in-Composition-A-Coffee-Table-Book-of-Poetry-and-Photos-by-Angel-Leya.pdf
    • http://loaminoo.linkpc.net/4090091096092098/Poetry-Changes-Lives-Daily-Thoughts-on-Poetry-and-History-by-Christopher-Burn.pdf
    • http://loaminoo.linkpc.net/8090097099097/Getting-Into-Poetry-A-Readers-and-Writers-Guide-to-the-Poetry-Scene-by-Paul-Hyland.pdf
    • http://loaminoo.linkpc.net/9092095093093093/My-poetry-depicts-you-An-anthology-of-contemporary-Kurdish-poetry-by-Rebwar-Fatah.pdf
    • http://loaminoo.linkpc.net/4095099093093093/Partial-Eclipse-A-Book-of-Poetry-Vassar-Miller-Prize-in-Poetry-1-by-Tony-Sanders.pdf
    • http://loaminoo.linkpc.net/1098092097098098/Poetry-180-A-Turning-Back-to-Poetry-by-Billy-Collins.pdf
    • http://loaminoo.linkpc.net/2090094093090091/The-Well-at-the-End-of-the-World-by-Robert-D-San-Souci.pdf
    • http://loaminoo.linkpc.net/4099095095095090/A-Boom-in-the-Room-an-Anthology-of-Student-Poetry-Student-Poetry-Anthologies-Book-1-by-Annie-Douglass-Lima.pdf
    • http://loaminoo.linkpc.net/2092092091098090