Malicious PDF — malware analysis report

Static analysis result for SHA-256 b8b3d6c0a9aa9065…

MALICIOUS

PDF

13.1 KB Created: 2019-05-02 17:15:36 +01:00 Authoring application: mPDF 5.7
MD5: 02d50446bd861be2bd10d08061a83bb3 SHA-1: 572d88b11989dbdf18557eff65602d9ed8048789 SHA-256: b8b3d6c0a9aa9065819fe8a5c2ce8882f1eae4747552e06667f4ae5edcd8b8ae
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on loaminoo.linkpc.net. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a link farm intended to drive traffic or potentially host malicious content. The ML classifier also flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9006

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6095093090090093/The-Winner-s-Curse-The-Winner-s-Trilogy-1-by-Marie-Rutkoski.pdf
    • http://loaminoo.linkpc.net/9099093097/The-Winner-s-Curse-The-Winner-s-Trilogy-1-by-Marie-Rutkoski.pdf
    • http://loaminoo.linkpc.net/3097091090091097/The-Korean-War-by-Max-Hastings.pdf
    • http://loaminoo.linkpc.net/4092090098092095/God-Wants-You-Dead-by-Sean-Hastings.pdf
    • http://loaminoo.linkpc.net/6096092093093090/Carrere-and-Hastings-by-Jesse-Russell.pdf
    • http://loaminoo.linkpc.net/5090094093097/Overlord-D-Day-and-the-Battle-for-Normandy-by-Max-Hastings.pdf
    • http://loaminoo.linkpc.net/8096093092094/Nearly-Departed-Weirdsville-1-by-Rook-Hastings.pdf
    • http://loaminoo.linkpc.net/1091090099093091096/Vote-Loki-3-by-Christopher-Hastings.pdf
    • http://loaminoo.linkpc.net/1091090099093091095/Vote-Loki-4-by-Christopher-Hastings.pdf
    • http://loaminoo.linkpc.net/2098094095093095/Catastrophe-1914-Europe-Goes-to-War-by-Max-Hastings.pdf
    • http://loaminoo.linkpc.net/8092094099091094/Cozy-Stanley-Hastings-14-by-Parnell-Hall.pdf
    • http://loaminoo.linkpc.net/6096092093092095/Carrere-amp-Hastings-Architects-by-Mark-A-Hewitt.pdf
    • http://loaminoo.linkpc.net/8091093091096/Retribution-The-Battle-for-Japan-1944-45-by-Max-Hastings.pdf
    • http://loaminoo.linkpc.net/2094093098096097/Visions-of-Chains-Awakening-3-by-Regan-Hastings.pdf
    • http://loaminoo.linkpc.net/3091096091094097/Another-Piece-of-the-Puzzle-Puppy-Development-by-Pat-Hastings.pdf
    • http://loaminoo.linkpc.net/7099097093099098/And-The-Winner-Is-by-Erin-Brady.pdf
    • http://loaminoo.linkpc.net/1090090097098099096/How-to-Look-Like-a-Winner-by-Dorothy-Woolfolk.pdf
    • http://loaminoo.linkpc.net/4096092094093099/For-the-Winner-by-Emily-Hauser.pdf
    • http://loaminoo.linkpc.net/4093099099098095/The-Winner-by-Melissa-Silvey.pdf
    • http://loaminoo.linkpc.net/4096092094091096/Vietnam-An-Epic-Tragedy-1945-1975-by-Max-Hastings.pdf