Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae3afdc5d2dd0531…

MALICIOUS

PDF

15.6 KB Created: 2019-05-07 03:17:23 +01:00 Authoring application: mPDF 5.7
MD5: eb5eaff34c5a5bae46a37add70135dc6 SHA-1: 4f3919c08a23a18ba08fe0ae337f4da0499ba1c9 SHA-256: ae3afdc5d2dd0531f1ee659e6a63c20d706bf37b3319684f451b9ad1978db334
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on loaminoo.linkpc.net. While the individual URLs are marked as benign, the sheer volume and the heuristic's classification suggest a malicious intent, possibly for SEO manipulation or as a distribution vector. No scripts were extracted from this sample. The ML_NYX_PDF_MALICIOUS classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7098095090099099/The-Alphabet-Sisters-Family-Baggage-by-Monica-McInerney.pdf
    • http://loaminoo.linkpc.net/1093099092/Taming-Lily-The-Fowler-Sisters-3-by-Monica-Murphy.pdf
    • http://loaminoo.linkpc.net/2090095099092/Her-Patchwork-Family-Gabriel-Sisters-2-by-Lyn-Cote.pdf
    • http://loaminoo.linkpc.net/4094094095095092/Family-Reunion-The-Downing-Sisters-2-by-Jill-Metcalf.pdf
    • http://loaminoo.linkpc.net/2096095099095098/Murder-Runs-in-the-Family-Southern-Sisters-3-by-Anne-George.pdf
    • http://loaminoo.linkpc.net/8091093093096098/The-Alphabet-Family-Eva-Montanari-by-Eva-Montanari.pdf
    • http://loaminoo.linkpc.net/2093096095099096/Monica-Speaks-Genuine-Pearls-of-Wisdom-from-America-s-Most-Famous-White-House-Intern-by-Monica-Lewinsky.pdf
    • http://loaminoo.linkpc.net/9096091092091093/The-Haas-Sisters-of-Franklin-Street-A-San-Francisco-Memoir-of-Family-and-Love-by-Frances-Bransten-Rothmann.pdf
    • http://loaminoo.linkpc.net/2096090099090092/Alphabet-Soup-Alphabet-Soup-1-Russian-Bear-2-by-C-B-Conwy.pdf
    • http://loaminoo.linkpc.net/4093092093092092/Baggage-by-S-G-Redling.pdf
    • http://loaminoo.linkpc.net/7098095090092099/The-Queen-And-I-by-Jay-McInerney.pdf
    • http://loaminoo.linkpc.net/7098094097098092/How-it-Ended-by-Jay-McInerney.pdf
    • http://loaminoo.linkpc.net/1099091092095091/Baggage-by-Emily-Barr.pdf
    • http://loaminoo.linkpc.net/1097090090094096/Story-of-My-Life-by-Jay-McInerney.pdf
    • http://loaminoo.linkpc.net/4094090095090094/The-Glorious-Heresies-by-Lisa-McInerney.pdf
    • http://loaminoo.linkpc.net/3093094099092092/The-Glorious-Heresies-by-Lisa-McInerney.pdf
    • http://loaminoo.linkpc.net/2092094094099094/Xcess-Baggage-by-Varsha-Dixit.pdf
    • http://loaminoo.linkpc.net/2099094093098090/The-Pumilio-Child-by-Judy-McInerney.pdf
    • http://loaminoo.linkpc.net/8096092097098092/Big-Theories-Revisited-by-Dennis-Michael-McInerney.pdf
    • http://loaminoo.linkpc.net/2092096091099094/No-Baggage-A-Tale-of-Love-and-Wandering-by-Clara-Bensen.pdf