Malicious PDF — malware analysis report

Static analysis result for SHA-256 beaca00523d6e83e…

MALICIOUS

PDF

15.4 KB Created: 2019-04-30 04:35:28 +01:00 Authoring application: mPDF 5.7
MD5: 322ba1e139d4b88c406e786e7d31ad1e SHA-1: b71e7fa3f7ba2662ffef9d79002344dd128b6591 SHA-256: beaca00523d6e83e5c97740ce4c2bea1127ac9bdd9651b85c923f13ea850c664
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, forming a link farm. While most of these URLs were classified as benign, the sheer volume and the heuristic firing of PDF_SEO_LINK_FARM suggest a malicious intent, likely to manipulate search engine results or to serve as a distribution point for other malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093099097098095/Kiwi-and-the-Missing-Magic-Kiwi-Series-2-by-Vickie-Johnstone.pdf
    • http://loaminoo.linkpc.net/2093099097098094/Kiwi-and-the-Living-Nightmare-Kiwi-Series-3-by-Vickie-Johnstone.pdf
    • http://loaminoo.linkpc.net/2093099097098096/Kiwi-in-Cat-City-Kiwi-Series-1-by-Vickie-Johnstone.pdf
    • http://loaminoo.linkpc.net/1090097091095093090/The-Jaded-Kiwi-by-Nick-Spill.pdf
    • http://loaminoo.linkpc.net/4096095091097098/His-Hired-Girlfriend-Kiwi-Bride-1-by-Alexia-Praks.pdf
    • http://loaminoo.linkpc.net/1098095090094092/Bruce-Goes-Home-Kiwi-Critters-Book-3-by-Donna-Blaber.pdf
    • http://loaminoo.linkpc.net/5091092098098/Adlai-Stevenson-and-the-World-The-Life-of-Adlai-E-Stevenson-by-John-Bartlow-Martin.pdf
    • http://loaminoo.linkpc.net/1090096098091091094/Kidnapped-By-Robert-Louis-Stevenson-Illustrated-FREE-Gulliver-s-Travels-by-Robert-Louis-Stevenson.pdf
    • http://loaminoo.linkpc.net/1091092096097090098/The-Master-of-Ballantrae-by-Robert-Louis-Stevenson-Unabridged-1889-Original-by-Robert-Louis-Stevenson.pdf
    • http://loaminoo.linkpc.net/4095090097093092/Tracks-by-Niv-Kaplan.pdf
    • http://loaminoo.linkpc.net/4098097090095094/Along-the-Tracks-by-Tamar-Bergman.pdf
    • http://loaminoo.linkpc.net/4096090099096096/Tracks-by-Louise-Erdrich.pdf
    • http://loaminoo.linkpc.net/2090091097096090/Destiny-on-the-Tracks-by-Drake-Braxton.pdf
    • http://loaminoo.linkpc.net/1090099092091091/Making-Tracks-by-Scott-G-Gibson.pdf
    • http://loaminoo.linkpc.net/8093095091095/Tracks-to-Murder-by-Jonathan-Goodman.pdf
    • http://loaminoo.linkpc.net/4095098095097/Tracks-in-the-Wild-by-Betsy-Bowen.pdf
    • http://loaminoo.linkpc.net/9097091098099096/Dismantling-the-Tracks-by-D-evad-Karahasan.pdf
    • http://loaminoo.linkpc.net/1093092098094096/Once-Upon-the-Tracks-of-Mumbai-by-Rishi-Vohra.pdf
    • http://loaminoo.linkpc.net/7090092093096094/Tear-Tracks-by-Malka-Ann-Older.pdf
    • http://loaminoo.linkpc.net/2090092092098092/Tracks-To-Love-by-Abbie-St-Claire.pdf
    • http://loaminoo.linkpc.net/1090096098091091094/Kidnapped-By-Robert-Louis-Stevenson-Illustrated-FREE-Gulliver-s-Travels-by-Robert-Louis