Malicious PDF — malware analysis report

Static analysis result for SHA-256 c14bd0d68e3793bc…

MALICIOUS

PDF

15.1 KB Created: 2019-04-30 04:55:01 +01:00 Authoring application: mPDF 5.7
MD5: 254f58a0103f5ef2ef9584e52bb6acd7 SHA-1: 5f785500dd712be5ca23b5d397a757dae531d15f SHA-256: c14bd0d68e3793bcb0d0052ec28517b3a6abf5a70327d9d06dedbfe9b4768916
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. The ML_NYX_PDF_MALICIOUS heuristic further supports its malicious nature. While the specific intent of the links is unclear, the sheer volume and the heuristic firing indicate a malicious purpose, likely related to SEO manipulation or distributing further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6094091090097097/The-Charge-of-the-Goddess---The-Poetry-of-Doreen-Valiente-by-Doreen-Valiente.pdf
    • http://loaminoo.linkpc.net/6094091090094096/Natural-Magic-by-Doreen-Valiente.pdf
    • http://loaminoo.linkpc.net/6092097094097093/Witchcraft-for-Tomorrow-by-Doreen-Valiente.pdf
    • http://loaminoo.linkpc.net/6094091090094099/The-Rebirth-of-Witchcraft-by-Doreen-Valiente.pdf
    • http://loaminoo.linkpc.net/6094091090095095/Witchcraft-A-Tradition-Renewed-by-Doreen-Valiente.pdf
    • http://loaminoo.linkpc.net/3096094094095093/Cats-in-the-Belfry-Doreen-Tovey-Cat-Books-by-Doreen-Tovey.pdf
    • http://loaminoo.linkpc.net/3094096096093099/Taming-The-Bitch-Valiente-1-by-Neilani-Alejandrino.pdf
    • http://loaminoo.linkpc.net/6094091090095099/The-Adventures-of-Don-Valiente-and-the-Apache-Canyon-Kid-by-Mary-W-Walters.pdf
    • http://loaminoo.linkpc.net/6094091091098097/El-Despertar-Del-Valiente-Reyes-y-Hechiceros-Libro-2-by-Morgan-Rice.pdf
    • http://loaminoo.linkpc.net/6094091090097094/Problemas-De-Balance-De-Materia-Y-Energia-En-La-Industria-Alimentaria-Problems-of-Matter-Balance-and-Energy-in-the-Food-Industry-by-Antonio-Valiente.pdf
    • http://loaminoo.linkpc.net/1097097099093095/Cats-In-May-by-Doreen-Tovey.pdf
    • http://loaminoo.linkpc.net/4093095097092093/No-One-But-Madison-by-Doreen-Orsini.pdf
    • http://loaminoo.linkpc.net/1098099092090098/Undeniable-by-Doreen-Orsini.pdf
    • http://loaminoo.linkpc.net/3095098095098092/Smick-by-Doreen-Cronin.pdf
    • http://loaminoo.linkpc.net/4090098098094096/Doreen-by-Barbara-Noble.pdf
    • http://loaminoo.linkpc.net/1093099098093096/Sex-and-Cognition-by-Doreen-Kimura.pdf
    • http://loaminoo.linkpc.net/3099094094096090/Her-Backyard-by-Doreen-Lewis.pdf
    • http://loaminoo.linkpc.net/7095092092094095/The-Highwayman-by-Doreen-Owens-Malek.pdf
    • http://loaminoo.linkpc.net/7095092095090094/Unsuitable-by-Doreen-Owens-Malek.pdf
    • http://loaminoo.linkpc.net/9097094091091/Adventures-in-Mother-Sitting-by-Doreen-Cox.pdf
    • http://loaminoo.linkpc.net/6094091090097094/Problemas-De-Balance-De-Materia-Y-Energia-En-La-Industria-Alimentaria-Problems-of-Matter-Balance-and-Energy-in-t