Malicious PDF — malware analysis report

Static analysis result for SHA-256 b10aeb7eaadab675…

MALICIOUS

PDF

15.8 KB Created: 2019-05-03 12:49:57 +01:00 Authoring application: mPDF 5.7
MD5: 249e57a4fa5ce0e65731e59970bac93e SHA-1: c0cbb183db8d4bed6a0642121f6eefcd119db5e2 SHA-256: b10aeb7eaadab675383474bfdfc195de2d6c0bff70e9b42bc133d87ab5fe2215
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to distribute further malware. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1093098092090/Lyddie-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/1098096098099095/Jacob-Have-I-Loved-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/5099092096094095/Bridge-to-Terabithia-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/2091098093092095/Bread-and-Roses-Too-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/2093099096091095/Jacob-Have-I-Loved-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/5093092090097097/Le-secret-de-T-rabithia-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/3092098096091096/Bridge-to-Terabithia-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/1098092097092090/Jacob-Have-I-Loved-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/1093099099097/Come-Sing-Jimmy-Jo-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/1093092095092/The-Flint-Heart-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/8093098091096099/Bridge-to-Terabithia-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/1094091094095/Jacob-Have-I-Loved-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/1090092097092092090/Marvin-s-Best-Christmas-Present-Ever-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/1091096098098090097/Bridge-to-Terabithia--by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/4098090094091095/The-Wide-Awake-Princess-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/2099092099095099/Angels-and-Other-Strangers-Family-Christmas-Stories-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/1099096098090098/God-s-Chinese-Son-The-Taiping-Heavenly-Kingdom-of-Hong-Xiuquan-by-Jonathan-D-Spence.pdf
    • http://loaminoo.linkpc.net/2099090092090091/Brother-Sun-Sister-Moon-Saint-Francis-of-Assisi-s-Canticle-of-the-Creatures-by-Katherine-Paterson.pdf
    • http://loaminoo.linkpc.net/1096095091096097/Autumn-in-the-Heavenly-Kingdom-China-the-West-and-the-Epic-Story-of-the-Taiping-Civil-War-by-Stephen-R-Platt.pdf
    • http://loaminoo.linkpc.net/1099091092099090/The-Heavenly-Horse-from-the-Outermost-West-Heavenly-Horse-1-by-Mary-Stanton.pdf
    • http://loaminoo.linkpc.net/1091096098098090097/Bridge-to-Terabithia--by-Katherin