Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3e6a1c8c7240bdf…

MALICIOUS

PDF

19.6 KB Created: 2019-04-30 04:27:50 +01:00 Authoring application: mPDF 5.7
MD5: 33f1a295600913f12aaecfdeeb2d59dd SHA-1: 8399846d6659ea9a5e644acc1cbec2f4f6724d04 SHA-256: b3e6a1c8c7240bdf520e997ee9e01afe9d9157653ce16e082c385552e4b80d28
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign-looking book titles, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malware. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9940

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099091099090099/Small-Bamboo-Growing-Up-and-Growing-Old-With-My-Vietnamese-Australian-Family-by-Tracy-Vo.pdf
    • http://loaminoo.linkpc.net/6093099094095/Small-Business-Management-Launching-and-Growing-Entrepreneurial-Ventures-by-Justin-G-Longenecker.pdf
    • http://loaminoo.linkpc.net/9098093096090/Growing-Up-in-Levittown-Again-Growing-Up-in-Levittown-Again-1-by-Molly-Maguire-McGill.pdf
    • http://loaminoo.linkpc.net/5093096095093/Waiting-for-Birdy-A-Year-of-Frantic-Tedium-Neurotic-Angst-and-the-Wild-Magic-of-Growing-a-Family-by-Catherine-Newman.pdf
    • http://loaminoo.linkpc.net/4092090095094096/The-Mom-s-Guide-to-Growing-Your-Family-Green-Saving-the-Earth-Begins-at-Home-Stonesong-Press-Books-by-Terra-Wellington.pdf
    • http://loaminoo.linkpc.net/6091090098096096/Vertical-Gardening-and-Container-Gardening-Ideas-for-Growing-Vegetables-and-Herbs-In-Small-Vertical-Places-Outdoors-and-Indoors-by-Joe-Marshall.pdf
    • http://loaminoo.linkpc.net/4096098096097094/Growing-Up-by-Clarissa-Carlyle.pdf
    • http://loaminoo.linkpc.net/6094092093091096/Growing-Pains-by-N-H-Kleinbaum.pdf
    • http://loaminoo.linkpc.net/8090090099096/A-Growing-Season-by-Sue-Boggio.pdf
    • http://loaminoo.linkpc.net/1091093098091094/Growing-Up-with-the-River-by-Dan-Burkhardt.pdf
    • http://loaminoo.linkpc.net/4094098098092092/Growing-Up-Twice-by-Rowan-Coleman.pdf
    • http://loaminoo.linkpc.net/4092093096099093/Growing-Up-X-by-Ilyasah-Shabazz.pdf
    • http://loaminoo.linkpc.net/1091096099093091/The-Growing-by-Susanne-M-Beck.pdf
    • http://loaminoo.linkpc.net/1090099093099095/Well-This-Is-Growing-Up-by-Megan-Street.pdf
    • http://loaminoo.linkpc.net/4093098094094/Tweak-Growing-Up-On-Methamphetamines-by-Nic-Sheff.pdf
    • http://loaminoo.linkpc.net/6094097098096099/Growing-Up-Claus-by-Corina-Zurcher.pdf
    • http://loaminoo.linkpc.net/9098091097090098/Growing-In-Joy-God-s-Way-To-Increase-Joy-In-All-Of-Life-by-Ron-Klug.pdf
    • http://loaminoo.linkpc.net/5098091094097092/Growing-Up-in-Slavery-by-Sylviane-A-Diouf.pdf
    • http://loaminoo.linkpc.net/3093093090098096/Growing-a-New-Tail-by-Lisa-C-Taylor.pdf
    • http://loaminoo.linkpc.net/9094092093090097/Growing-Closer-to-God-Ldr-by-Jessie-Schut.pdf
    • http://loaminoo.linkpc.net/4092090095094096/The-Mom-s-Guide-to-Growing-Your-Family-Gr