Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd712670c6604f2e…

MALICIOUS

PDF

16.2 KB Created: 2019-05-02 05:41:11 +01:00 Authoring application: mPDF 5.7
MD5: 0341a76242a2979930d994e9746ac962 SHA-1: ba007bc813a101f0dcb5f099a1929f2416680abe SHA-256: bd712670c6604f2e2c791462d972e0a3ba4925572fa308c7496a29b4e1f4e494
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates this is a malicious technique to distribute content or redirect users. While the specific intent of the links is unclear, the sheer volume and the 'PDF_SEO_LINK_FARM' heuristic strongly suggest a malicious purpose, likely for phishing or malware delivery. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097096097093/The-Birr-Elixir-The-Legend-of-the-Gamesmen-1-by-Jo-Sparkes.pdf
    • http://loaminoo.linkpc.net/2091093097098096/The-Birr-Elixir-The-Legend-of-the-Gamesmen-1-by-Jo-Sparkes.pdf
    • http://loaminoo.linkpc.net/4092092091097093/Emily-Sparkes-and-the-Disco-Disaster-Emily-Sparkes-3-by-Ruth-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/3091099099098/Wishful-Thinking-by-Ali-Sparkes.pdf
    • http://loaminoo.linkpc.net/6098091099094/Finding-the-Fox-The-Shapeshifter-1-by-Ali-Sparkes.pdf
    • http://loaminoo.linkpc.net/4093096091096093/The-Cost-of-Bravery-by-Allan-Sparkes.pdf
    • http://loaminoo.linkpc.net/3090090098099/Elixir-by-Ted-Galdi.pdf
    • http://loaminoo.linkpc.net/4098094096096091/Elixir-by-Edward-B-Farber.pdf
    • http://loaminoo.linkpc.net/2091092092092094/Elixir-Bound-by-Katie-L-Carroll.pdf
    • http://loaminoo.linkpc.net/3094090096092/Elixir-Covenant-3-5-by-Jennifer-L-Armentrout.pdf
    • http://loaminoo.linkpc.net/8094096091092092/-tudes-for-Elixir-by-J-David-Eisenberg.pdf
    • http://loaminoo.linkpc.net/4099098096096090/Elixir-Covenant-3-5-by-Jennifer-L-Armentrout.pdf
    • http://loaminoo.linkpc.net/4096097099096/True-Elixir-3-by-Hilary-Duff.pdf
    • http://loaminoo.linkpc.net/4097093092094099/Legend-Series-sampler-featuring-excerpts-from-Legend-and-Prodigy-by-Marie-Lu.pdf
    • http://loaminoo.linkpc.net/9099092096091/The-Red-Lion-The-Elixir-of-Eternal-Life-by-M-ria-Szepes.pdf
    • http://loaminoo.linkpc.net/9092098092091098/The-Child-Du-kannst-die-Vergangenheit-begraben-aber-die-Wahrheit-lebt-weiter-Detective-Bob-Sparkes-2-by-Fiona-Barton.pdf
    • http://loaminoo.linkpc.net/2092094094090096/Elixir-Channeling-Morpheus-Sweet-Oblivion-10-by-Jordan-Castillo-Price.pdf
    • http://loaminoo.linkpc.net/1097097092090098/Shades-of-the-Stars-A-Legend-of-the-Dreamer-Anthology-Legend-of-the-Dreamer-1-5-by-David-James.pdf
    • http://loaminoo.linkpc.net/2093095093090096/Dorrie-and-the-Amazing-Magic-Elixir-Dorrie-the-Little-Witch-11-by-Patricia-Coombs.pdf
    • http://loaminoo.linkpc.net/1090090090099095094/Pack-The-Legend-of-Zelda-The-Legend-of-Zelda-1-5-by-Akira-Himekawa.pdf
    • http://loaminoo.linkpc.net/4097093092094099/Legend-Series-sampler-featuring-excerpts-from-Legend-and-Pr