Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba6413b53f3b8311…

MALICIOUS

PDF

14.3 KB Created: 2019-05-05 15:56:44 +01:00 Authoring application: mPDF 5.7
MD5: b564235a3c283adf53f7eb86466cf0d4 SHA-1: d458ba681391f1c47524744c4ea760248d918ec0 SHA-256: ba6413b53f3b8311fad9a8fa9f4ebdd051299f577b378b0a2a8203eae8c05cc8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on loaminoo.linkpc.net. While these specific URLs are marked as benign, the sheer volume and structure suggest a link farm or redirection mechanism. The ML_NYX_PDF_MALICIOUS heuristic also flagged the file with high confidence. No scripts were extracted from this sample. The primary attack pattern appears to be the distribution of a large number of links, potentially to manipulate search engine results or to serve as a distribution point for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096094092093/The-Hiding-Place-by-Trezza-Azzopardi.pdf
    • http://loaminoo.linkpc.net/1091098093099096098/Remember-Remember-The-Fifth-Of-November-The-History-Of-Britain-In-Bite-Sized-Chunks-by-Judy-Parkinson.pdf
    • http://loaminoo.linkpc.net/8098092092098/Because-I-Remember-Terror-Father-I-Remember-You-by-Sue-William-Silverman.pdf
    • http://loaminoo.linkpc.net/3096098099096095/Remember-When-3-The-Finale-Remember-Trilogy-3-by-T-Torrest.pdf
    • http://loaminoo.linkpc.net/4092096094096093/Remember-Me-Remember-Me-1-by-Christopher-Pike.pdf
    • http://loaminoo.linkpc.net/3098095090090/Remember-Me-Remember-Me-1-3-by-Christopher-Pike.pdf
    • http://loaminoo.linkpc.net/2097090096099094/I-Remember-You-I-Remember-You-1-by-Scarlett-Metal.pdf
    • http://loaminoo.linkpc.net/9098095094092094/The-Parts-I-Remember-The-Parts-I-Remember-1-by-A-K-Mills.pdf
    • http://loaminoo.linkpc.net/2097098097095097/Remember-by-Rin-Haven.pdf
    • http://loaminoo.linkpc.net/2099090094091097/Remember-When-by-A-D-Ryan.pdf
    • http://loaminoo.linkpc.net/1091091098090/Always-to-Remember-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/4091094092096091/We-Will-Remember-by-Elizabeth-Darrell.pdf
    • http://loaminoo.linkpc.net/1091090098095090090/A-Summer-To-Remember-by-Ron-Dieb.pdf
    • http://loaminoo.linkpc.net/2097096096091098/Remember-Newvember-by-J-M-Bogart.pdf
    • http://loaminoo.linkpc.net/3091090094091099/Something-to-Remember-Something-Series-by-K-S-Micheli.pdf
    • http://loaminoo.linkpc.net/3099094095096091/Remember-Newvember-by-J-M-Bogart.pdf
    • http://loaminoo.linkpc.net/2090097090094095/All-That-We-Remember-by-Elenor-Gill.pdf
    • http://loaminoo.linkpc.net/1099094095095097/I-Remember-You-by-Yrsa-Sigur-ard-ttir.pdf
    • http://loaminoo.linkpc.net/9091097091090/Don-t-You-Remember-by-Lucille-Clifton.pdf
    • http://loaminoo.linkpc.net/2099092092091092/Remember-Me-by-Sophie-Kinsella.pdf
    • http://loaminoo.linkpc.net/2099