Malicious PDF — malware analysis report

Static analysis result for SHA-256 b24aeeb4ea3b992a…

MALICIOUS

PDF

15.5 KB Created: 2019-05-01 20:45:38 +01:00 Authoring application: mPDF 5.7
MD5: 26aed5e8270c67cea9c3bac49354b9ba SHA-1: 1dbdfe12d40fc2e454d30ca6932faa0a2515a075 SHA-256: b24aeeb4ea3b992a0c37b22b4197f662737e66efdd23141faaed0328c9fe3d2d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by an ML classifier as malicious and contains a large number of embedded URLs, indicating a potential link farm or distribution mechanism. The heuristic PDF_SEO_LINK_FARM specifically calls out the mass external PDF link farm, with the first URL being http://loaminoo.linkpc.net/4091096093099095/Minding-Molly-The-Courtships-of-Lancaster-County-3-by-Leslie-Gould.pdf. While the document body is heavily obfuscated, the presence of numerous links suggests an attempt to lure users to malicious content or manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4091096093099095/Minding-Molly-The-Courtships-of-Lancaster-County-3-by-Leslie-Gould.pdf
    • http://loaminoo.linkpc.net/4093098094092097/Amish-Weddings-Neighbors-of-Lancaster-County-3-by-Leslie-Gould.pdf
    • http://loaminoo.linkpc.net/4099099098090091/The-Amish-Mother-Lancaster-Courtships-2-by-Rebecca-Kertz.pdf
    • http://loaminoo.linkpc.net/1091091098091098098/Courting-Cate-by-Leslie-Gould.pdf
    • http://loaminoo.linkpc.net/5090091090094099/Tender-Mercies-Men-of-Lancaster-County-2-by-Eli-Easton.pdf
    • http://loaminoo.linkpc.net/1093098090094095/The-Reckoning-The-Heritage-of-Lancaster-County-3-by-Beverly-Lewis.pdf
    • http://loaminoo.linkpc.net/4095090093098097/The-Shunning-The-Heritage-of-Lancaster-County-1-by-Beverly-Lewis.pdf
    • http://loaminoo.linkpc.net/1091097091092092094/An-Amish-Gathering-Life-in-Lancaster-County-by-Beth-Wiseman.pdf
    • http://loaminoo.linkpc.net/3092093098091096/Plain-and-Fancy-Brides-of-Lancaster-County-3-by-Wanda-E-Brunstetter.pdf
    • http://loaminoo.linkpc.net/1091097091092092092/A-Merry-Heart-Brides-of-Lancaster-County-1-by-Wanda-E-Brunstetter.pdf
    • http://loaminoo.linkpc.net/3092093098094091/The-Choice-Lancaster-County-Secrets-1-by-Suzanne-Woods-Fisher.pdf
    • http://loaminoo.linkpc.net/5096096094096/The-Storekeeper-s-Daughter-Daughters-of-Lancaster-County-1-by-Wanda-E-Brunstetter.pdf
    • http://loaminoo.linkpc.net/3097091090098099/An-Amish-Christmas-December-in-Lancaster-County-by-Beth-Wiseman.pdf
    • http://loaminoo.linkpc.net/5097094097096/The-Waiting-Lancaster-County-Secrets-2-by-Suzanne-Woods-Fisher.pdf
    • http://loaminoo.linkpc.net/4098099097097092/The-Amish-Nanny-The-Women-of-Lancaster-County-2-by-Mindy-Starns-Clark.pdf
    • http://loaminoo.linkpc.net/4093098097093091/A-Secret-Amish-Love-Women-of-Lancaster-County-1-by-Rebecca-Kertz.pdf
    • http://loaminoo.linkpc.net/2095098095090092/After-the-Fire-The-Destruction-of-the-Lancaster-County-Amish-by-Randy-Michael-Testa.pdf
    • http://loaminoo.linkpc.net/2096096096093091/Beacon-s-Call-Miracles-of-Marble-Cove-4-by-Leslie-Gould.pdf
    • http://loaminoo.linkpc.net/8098094090090/Emma-s-Choice-The-Zook-Sisters-of-Lancaster-County-2-by-June-Bryan-Belfie.pdf
    • http://loaminoo.linkpc.net/8093094091094/Chester-Gould-A-Daughter-s-Biography-of-the-Creator-of-quot-Dick-Tracy-quot-by-Jean-Gould-O-39-connell.pdf
    • http://loaminoo.linkpc.net/5096096094096/The-Storekeeper-s-Daughter-Daughte