Malicious PDF — malware analysis report

Static analysis result for SHA-256 b17806b546a04867…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 04:00:00 +01:00 Authoring application: mPDF 5.7
MD5: ccba7f392eb0f70cbfc0ae8b23251434 SHA-1: 62a0bc521bec9a7a489628ac85bc0e3f21e9a395 SHA-256: b17806b546a048673e66617aae47e64e4c97cf73766342a7341685b4a749cba6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/9098095092096090/The-Green-Mile-Parts-1-6-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/1090097092093095/The-Green-Mile-Part-1-The-Two-Dead-Girls-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4096099095099/The-Green-Mile-Part-1-The-Two-Dead-Girls-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/3092095093097094/Screenplays-by-Stephen-King-Rose-Red-Kingdom-Hospital-Creepshow-the-Stand-Children-of-the-Corn-Cat-s-Eye-Pet-Sematary-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/1091095098098095090/STEPHEN-KING-NEW-COVER-SERIES-No-10-JOYLAND-ILLUSTRATED---1-500-by-Stephen-King-based-on-a-book-by-.pdf
    • http://loaminoo.linkpc.net/6092092091092099/Dolores-Claiborne-Nightmares-and-Dreamscapes-Stephen-King-11-2-boxed-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4092091090094099/Stephen-King-Goes-to-the-Movies-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/6097094094093091/King-Goes-to-the-Movies-Vijf-verfilmde-verhalen-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/3091090092092098/Green-Smoothie-Everyday-Green-Smoothie-For-Beginners-10-Day-Green-Smoothie-Cleanse-green-smoothies-green-smoothies-detox-green-smoothies-recipes-green-Diet-healthy-food-for-everyday-Book-9-by-Anna-Scott.pdf
    • http://loaminoo.linkpc.net/5096096098096/The-Mark-of-the-King-by-Jocelyn-Green.pdf
    • http://loaminoo.linkpc.net/4094091099094/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/9096092096/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4099090094091096/UR-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4095094097098096/It-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/7091091095098097/It-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/2096093098093/It-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4096095092093/UR-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4096094093095099/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/8094097099091/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/5092096099092097/Mobiel-by-Stephen-King.pdf