Malicious PDF — malware analysis report

Static analysis result for SHA-256 be55d636c994261f…

MALICIOUS

PDF

37.3 KB Created: 2019-05-02 05:10:22 +01:00 Authoring application: mPDF 5.7
MD5: 9cf5f348813e000fca021d11bf93ef57 SHA-1: 74ff7610422f39d756cb6761a51530c3c6c66fa0 SHA-256: be55d636c994261fbe56bf20e96f0c5b7821765d8911d511fe9a9beba621b85e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files. The ML classifier also flagged this as malicious. The embedded URLs are likely part of a link farm designed to attract traffic or distribute further malicious content, although the specific URLs themselves were classified as benign. The attack pattern is consistent with a phishing or traffic distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9695

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3091093093097092/Halloween-Stories-for-Kids-amp-More-17-Assorted-Stories-to-Read-with-Kids-at-Halloween-Bonus-Halloween-Party-Story-Kids-Story-Bundle-Children-s-Series-Spooky-Scary-Funny-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091093097090098/Stories-For-Kids-amp-Teens-Includes-16-Original-Stories-with-Covers-Funny-Kids-Stories-Childrens-Book-Bundle-Animals-Character-Building-Lessons-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/7096096096096091/23-Halloween-Crafts-for-Kids-Homemade-Halloween-Costume-Ideas-and-Spooky-Decor-by-Prime-Publishing.pdf
    • http://loaminoo.linkpc.net/3091093093090090/Children-s-Adventure-Story-Bundle-5-4-Books-in-1-Kids-Bedtime-Stories-Collection-Books-about-music-life-animals-planets-Family-Coming-of-age-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091093097092093/New-Readers-Story-Collection-4-15-Books-in-1-Easy-to-Read-and-Follow-Bedtime-Stories-for-Kids-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091093090093098/Short-Funny-Stories-For-Kids-Happy-Tales-for-Happy-Kids-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091093096096093/MAGICAL-ASSORTMENT-OF-SHORT-KIDS-STORIES-14-Stories-in-1-KIDS-BOOK-PICTURES-BOOK-CHILDREN-S-BOOK-PRE-SCHOOL-FAIRLY-TALE-EARLY-LEARNING-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091093096094090/Short-Elementary-Level-Stories-Bundle-2-3-Short-Stories-in-1-Ebook-Books-about-Santa-mystery-space-animals-planets-family-Perfect-for-kids-under-10-learning-to-read-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091093094099099/Stories-Kids-Learn-From-19-Short-Stories-for-Growing-Kids-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091093094092090/Fun-To-Read-Kids-Stories-7-15-All-Ages-Stories-in-1-Book-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091093094093092/Short-Stories-for-Girls-and-Young-Women-2-Bundle-Includes-an-Assortment-of-15-Short-Stories-Kids-Storybooks-Series-Diaries-Space-Christmas-Adventure-Science-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/3091092093091097/Books-for-Kids-Tommy-Tiger-Visits-Veggie-World-Illustration-Book-Ages-3-8-Short-Stories-for-Kids-Kids-Books-Bedtime-Stories-For-Kids-Children-Books-Early-Readers-by-Tommy-Tiger.pdf
    • http://loaminoo.linkpc.net/3091092092092093/Books-for-Kids-Tommy-Tiger-and-the-Football-Fear-Illustration-Book-Ages-3-8-Short-Stories-for-Kids-Kids-Books-Bedtime-Stories-For-Kids-Children-Books-Early-Readers-by-Tommy-Tiger.pdf
    • http://loaminoo.linkpc.net/4093095093099091/Books-for-Children---I-Promise-Good-Dream-Story-4-Free-Kids-Books-Beginning-Reader-Bedtime-Stories-For-Kids-Ages-3-8-children-s-books-by-Aurora-Higgins.pdf
    • http://loaminoo.linkpc.net/4093095090097093/Books-for-Children---My-Best-Unicorn-Good-Dream-Story-2-Free-Kids-Books-Beginning-Reader-Bedtime-Stories-For-Kids-Ages-3-8-children-s-books-by-Aurora-Higgins.pdf
    • http://loaminoo.linkpc.net/3091093093091094/Early-Reading-Challenge-10-Bundle-with-15-stories-Beginner-readers-Adventure-Animal-stories-Teach-Values-Book-Funny-free-story-prime-Rhymes-Fantasy-Education-by-Betty-J-Byers.pdf
    • http://loaminoo.linkpc.net/1099099090090092/Books-for-Kids-Superhero-Puppy-Dog-Bedtime-Stories-For-Kids-Ages-3-10-children-s-books---Bedtime-Stories-For-Kids-by-S-J-Walter.pdf
    • http://loaminoo.linkpc.net/3091092097097091/Books-for-Kids-Super-Ants-Illustration-Book-kids-books-Ages-3-8-Bedtime-Stories-For-Kids-Children-s-Books-beginner-reader-books-Bugs-amp-Spiders-1-by-Robot-J-.pdf
    • http://loaminoo.linkpc.net/3091092094099090/Books-for-Kids-The-Tortoise-amp-The-Hare-Illustration-Book-kids-books-Ages-3-8-Bedtime-Stories-For-Kids-Children-s-Books-beginner-reader-books-turtle-1-by-Robot-J-.pdf
    • http://loaminoo.linkpc.net/3091092097092094/Books-for-Kids-THE-TRUE-RAY-OF-HOPE-Illustration-Book-kids-books-Ages-3-8-Bedtime-Stories-For-Kids-Children-s-Books-beginner-reader-books-by-Robot-J-.pdf
    • http://loaminoo.linkpc.net/3091093093090090/Children-s-Adventure-Story-Bundle-5-4-Books-in-1-Ki