Malicious PDF — malware analysis report

Static analysis result for SHA-256 b54250c9af9a4a3a…

MALICIOUS

PDF

24.7 KB Created: 2019-05-04 12:54:14 +01:00 Authoring application: mPDF 5.7
MD5: 38bc3e81ebcaa5ddd11f4a09659318e1 SHA-1: f683d46f13398737ea11424d1eff7f0067d4dba0 SHA-256: b54250c9af9a4a3a66b6691b456770cc765d2183165c979b029cb5c0a107d9f4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. The ML classifier also flagged this PDF as malicious with high confidence. While the document body is unreadable, the presence of numerous links points towards a malicious intent, possibly for SEO poisoning or to direct users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7093095090094099/The-History-and-Adventures-of-the-Renowned-Don-Quixote-Translated-from-the-Spanish-of-Miguel-de-Cervantes-Saavedra-by-T-Smollet-M-D-the-Sixth-Edition-Corrected-in-Four-Volumes-Volume-4-of-4-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/1091091097090097093/The-History-of-Don-Quixote-de-la-Mancha-Great-Books-of-the-Western-World-29---Cervantes-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/5097094092096094/The-adventures-of-Don-Quixote-abridged-from-the-original-edition-by-W-M-Thackeray-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/6097098097091093/The-First-Part-of-the-Life-and-Achievements-of-the-Renowned-Don-Quixote-de-La-Mancha-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/7093094099091098/Don-Quixote-Translated-by-Edith-Grossman-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/5094098094091097/The-Adventures-of-Don-Quixote-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/7092097090094098/The-Adventures-of-Don-Quixote-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/7097092094090090/The-History-of-the-Renowned-Don-Quixote-de-La-Mancha-Including-Minutely-Every-Curious-Incident-Attending-His-Faithful-Squire-and-Servant-Sancho-Panza-Interspersed-with-Ludicrous-Dialogues-Rhapsodies-Madrigals-Ad-Serenades-the-Whole-Replete-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/7093096094096098/Don-Quixote-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/2094093097092/Don-Quixote-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/1091090092097097097/Don-Quixote---Vol-1-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/1090091099095094091/Don-Quixote-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/3096092098091097/Don-Quixote-de-La-Mancha-Vol-1-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/1090094091098093093/Don-Quixote-with-eBook-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/1090093091093092092/The-Ingenious-Gentleman-Don-Quixote-of-La-Mancha-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/7093095090096092/Complete-Works-of-Miguel-de-Cervantes-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/7098098092092094/Don-Quixote-Errant-Knight-and-Sane-Madman-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/5097099098092097/Don-Quixote-Black-Illustrated-Classics-Bonus-Free-Audiobook-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/3095090097098098/Don-Quixote-de-La-Mancha-II-Don-Quijote-de-la-Mancha-2-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/7093094099092097/The-Jealous-Extremaduran-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/5097094092096094/The-adventures-of-Don-Quixote-abridged-from-the-original-ed