Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0646932ac4a7b6a…

MALICIOUS

PDF

19.1 KB Created: 2019-05-05 16:45:04 +01:00 Authoring application: mPDF 5.7
MD5: b4048c316357842e93364a72a18dd348 SHA-1: c54a0c9f6d6af8e9034f3a9be0abee6041ed9782 SHA-256: c0646932ac4a7b6ac532b830445091aab4cbcdfba9793185825b71097a0160e3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on loaminoo.linkpc.net. While the URLs themselves are marked as benign, the sheer volume and nature of the links suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095095092098098/Owned-The-Billionaire-Banker-1-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/1097090090091095/Owned-The-Billionaire-Banker-1-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/7096091092095090/The-Billionaire-Banker-Series-Box-Set-1-3-The-Billionaire-Banker-1-3-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/4093093099092091/Exposed-The-Billionaire-Banker-2-1-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/1094095093099094/Forty-2-Days-The-Billionaire-Banker-2-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/2093092098093092/Dirty-Aristocrat-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/2099090094091091/Blind-Reader-Wanted-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/3095097098091096/Sexy-Beast-Gypsy-Heroes-1-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/7096091092097094/Wounded-Beast-Gypsy-Heroes-2-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/1097098093096097/Eden-II-The-Eden-Trilogy-2-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/2093092098092099/Eden-III-The-Eden-Trilogy-3-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/4094093098096092/Beautiful-Beast-Beast-3-by-Georgia-Le-Carre.pdf
    • http://loaminoo.linkpc.net/4097094091/The-Billionaire-s-Christmas-Virgin-Prelude-to-Billionaire-Unknown---Blake-The-Billionaire-s-Obsession-9-5-by-J-S-Scott.pdf
    • http://loaminoo.linkpc.net/2098091099092091/The-Billionaire-s-Passion-The-Billionaire-s-Kiss-Book-Four-A-Billionaire-Alpha-Romance-by-Olivia-Thorne.pdf
    • http://loaminoo.linkpc.net/4098099095090/John-Le-Carr-Three-Complete-Novels-Tinker-Tailor-Soldier-Spy-The-Honourable-Schoolboy-Smiley-s-People-by-John-le-Carr-.pdf
    • http://loaminoo.linkpc.net/1098095094097099/Drums-and-Shadows-Survival-Studies-among-the-Georgia-Coastal-Negroes-by-Georgia-Writers-39-Project.pdf
    • http://loaminoo.linkpc.net/9096092091098/Georgia-in-Hawaii-When-Georgia-O-Keeffe-Painted-What-She-Pleased-by-Amy-Novesky.pdf
    • http://loaminoo.linkpc.net/4099096097096093/Georgia-A-Novel-of-Georgia-O-Keeffe-by-Dawn-Tripp.pdf
    • http://loaminoo.linkpc.net/1094097092091099/Billionaire-Romance-Billionaire-A-Sizzling-Hot-Billionaire-Romance-Boxed-Set-Collection-by-J-L-Ryan.pdf
    • http://loaminoo.linkpc.net/4094090093096093/The-Billionaire-s-Stray-Heart-Burke-Billionaire-Romance-Book-2-by-Rachelle-J-Christensen.pdf