Malicious PDF — malware analysis report

Static analysis result for SHA-256 c208bcb065d4722b…

MALICIOUS

PDF

19.9 KB Created: 2019-05-02 00:44:45 +01:00 Authoring application: mPDF 5.7
MD5: 2515fb8e01b76e0327747aae1dacb0d1 SHA-1: 51e66dbd53c663afa56b09b970a78fb973a6e87f SHA-256: c208bcb065d4722b843c4357aae156f160f05275ac67195712f5552a779306af
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a link farm or redirection scheme. While the extracted URLs themselves are currently classified as benign, the sheer volume and pattern indicate a malicious intent to direct users to external resources. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9924

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5094090099096091/The-Adventures-of-Tom-Sawyer-Golden-Illustrated-Classics-Comes-with-a-Free-Audiobook-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/7096092092097090/The-Adventures-of-Tom-Sawyer-Illustrated-Free-Audio---Driver-Publishing-Classics-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/5094091090092098/Iliad-Golden-Illustrated-Classics-Comes-with-a-Free-Audiobook-by-Homer.pdf
    • http://loaminoo.linkpc.net/5094090099096090/The-Scarlet-Letter-Golden-Illustrated-Classics-Comes-with-a-Free-Audiobook-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/5094090098099097/A-Tale-Of-Two-Cities-Golden-Illustrated-Classics-Comes-with-a-Free-Audiobook-by-Charles-Dickens.pdf
    • http://loaminoo.linkpc.net/8095098091090094/The-Adventures-of-Tom-Sawyer---World-s-Popular-Classics-Series-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/5097099098092097/Don-Quixote-Black-Illustrated-Classics-Bonus-Free-Audiobook-by-Miguel-de-Cervantes-Saavedra.pdf
    • http://loaminoo.linkpc.net/1098090095098099/The-Adventures-of-Tom-Sawyer-Adventures-of-Huckleberry-Finn-The-Prince-amp-the-Pauper-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/7093092090092095/The-Adventures-of-Tom-Sawyer-Annotated-Signet-Edition-The-Adventures-of-Tom-and-Huck-Book-1-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/9096091090091093/The-Adventures-of-Tom-Sawyer-and-The-Adventures-of-Huckleberry-Finn-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/9093097091091094/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/8098094095097/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/7095093090096093/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/9098096092091093/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/3098097095096091/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/8091097093097094/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/9095099090096091/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/8097097096091095/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/7096090098096093/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/8091097094095096/The-Adventures-of-Tom-Sawyer-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/5094090098099097/A-Tale-Of-Two-Cities-Golden-Illustrated-Classics-Comes-with-a-Free-Audiobook-by-Charles-Dickens.p