Malicious PDF — malware analysis report

Static analysis result for SHA-256 c1826f3f6c76f12c…

MALICIOUS

PDF

21.3 KB Created: 2019-04-30 04:16:33 +01:00 Authoring application: mPDF 5.7
MD5: 08307e436a8712b3ebd319a04839f169 SHA-1: ab35ff6a0ebe7122fd077c36617ee179fc7d926a SHA-256: c1826f3f6c76f12c51ffba2bae9d3fcce5d938ccca3e57ac9e33e5b03a1bdfc2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted were marked as benign, the sheer volume and structure suggest a malicious intent, likely to manipulate search engine results or redirect users to potentially harmful content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9099097098098090/Histories-of-Sexuality-Antiquity-to-Sexual-Revolution-by-Stephen-Garton.pdf
    • http://loaminoo.linkpc.net/1091093091095096/The-Polish-Revolution-Solidarity-by-Timothy-Garton-Ash.pdf
    • http://loaminoo.linkpc.net/2095095098097098/Sexual-Meanings-The-Cultural-Construction-Of-Gender-And-Sexuality-by-Sherry-B-Ortner.pdf
    • http://loaminoo.linkpc.net/3092092091093092/The-Survivor-s-Guide-to-Sex-How-to-Create-Your-Own-Empowered-Sexuality-After-Childhood-Sexual-Abuse-by-Staci-K-Haines.pdf
    • http://loaminoo.linkpc.net/1091094093098095093/Moral-Revolution-The-Naked-Truth-About-Sexual-Purity-by-Kris-Vallotton.pdf
    • http://loaminoo.linkpc.net/7090093090094099/Sexing-the-Millenium-Political-History-of-the-Sexual-Revolution-by-Linda-Grant.pdf
    • http://loaminoo.linkpc.net/9097095095099091/Sex-in-Crisis-The-New-Sexual-Revolution-and-the-Future-of-American-Politics-by-Dagmar-Herzog.pdf
    • http://loaminoo.linkpc.net/1093098095092099/A-Tragic-Grace-The-Catholic-Church-and-Child-Sexual-Abuse-by-Stephen-J-Rossetti.pdf
    • http://loaminoo.linkpc.net/2097099095091099/The-French-Revolution-and-What-Went-Wrong-by-Stephen-Clarke.pdf
    • http://loaminoo.linkpc.net/7097093093095095/Punk-The-Definitive-Record-of-a-Revolution-by-Stephen-Colegrave.pdf
    • http://loaminoo.linkpc.net/7092096093093092/The-Sexual-Teachings-of-the-Jade-Dragon-Taoist-Methods-for-Male-Sexual-Revitalization-by-Hsi-Lai.pdf
    • http://loaminoo.linkpc.net/3095094099093091/The-Battle-of-St-Louis-The-Attack-on-Cahokia-and-the-American-Revolution-in-the-West-by-Stephen-L-Kling-Jr-.pdf
    • http://loaminoo.linkpc.net/1091092099098094094/Rush-Revolution-Madness-and-the-Visionary-Doctor-Who-Became-a-Founding-Father-by-Stephen-Fried.pdf
    • http://loaminoo.linkpc.net/1093095094096094/Erotic-Marriage-Break-Free-from-the-Negative-Sexual-Script-and-Improve-the-Sexual-and-Emotional-Quality-of-Your-Relationship-by-Frederick-D-Mondin.pdf
    • http://loaminoo.linkpc.net/8091098098093096/Kama-Sutra-Sexual-Positions-For-Him-And-For-Her-Sexual-Positions-For-Her-And-For-Him-by-Anne-Hooper.pdf
    • http://loaminoo.linkpc.net/9099097098096095/Pieces-of-Hate-by-Ray-Garton.pdf
    • http://loaminoo.linkpc.net/9099097099094092/Slivers-of-Bone-by-Ray-Garton.pdf
    • http://loaminoo.linkpc.net/9099097099095093/Invaders-From-Mars-by-Ray-Garton.pdf
    • http://loaminoo.linkpc.net/7098099094097094/Noodle-amp-Lou-by-Liz-Garton-Scanlon.pdf
    • http://loaminoo.linkpc.net/9099097098091096/Serpent-Girl-by-Ray-Garton.pdf