Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba9449bd93d22a95…

MALICIOUS

PDF

14.9 KB Created: 2019-05-02 22:42:56 +01:00 Authoring application: mPDF 5.7
MD5: a17f24c6b6ec9ab474d101651b0804ae SHA-1: 17f3dc4dcc8de9237c835df01d002e139dd182a3 SHA-256: ba9449bd93d22a954380d2c3cd56019faeb8aecd2978a36e03e2c150877cce7f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely for SEO poisoning or to redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3092095093097094/Screenplays-by-Stephen-King-Rose-Red-Kingdom-Hospital-Creepshow-the-Stand-Children-of-the-Corn-Cat-s-Eye-Pet-Sematary-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/1091095098098095090/STEPHEN-KING-NEW-COVER-SERIES-No-10-JOYLAND-ILLUSTRATED---1-500-by-Stephen-King-based-on-a-book-by-.pdf
    • http://loaminoo.linkpc.net/6092092091092099/Dolores-Claiborne-Nightmares-and-Dreamscapes-Stephen-King-11-2-boxed-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/9090099094095/Brunelleschi-s-Dome-How-a-Renaissance-Genius-Reinvented-Architecture-by-Ross-King.pdf
    • http://loaminoo.linkpc.net/1090097098096096097/The-Dome-The-Dome-Trilogy-1-by-Nova-Sparks.pdf
    • http://loaminoo.linkpc.net/4092091090094099/Stephen-King-Goes-to-the-Movies-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/6097094094093091/King-Goes-to-the-Movies-Vijf-verfilmde-verhalen-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4095094097098096/It-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4096095092093/UR-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/2096093098093/It-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/9096092096/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4096094093095099/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4094091099094/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4099090094091096/UR-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/8094097099091/11-22-63-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/7091091095098097/It-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4098094095092090/The-Stand-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/4095096093098098/Dreamcatcher-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/9094090091092/Creepshow-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/3098094099099097/Christine-by-Stephen-King.pdf
    • http://loaminoo.linkpc.net/