Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2134143143788c8…

MALICIOUS

PDF

15.1 KB Created: 2019-05-02 19:08:15 +01:00 Authoring application: mPDF 5.7
MD5: 199008ee2e7be16af81ac54cb2edd435 SHA-1: 3e5685bc19c844718bf285730b269f6ec9e807e3 SHA-256: c2134143143788c8eb882d41ab6e11e83e86d75e8783dc71a568bdaedf32692e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs were individually confirmed as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/8091091096090099/The-Big-Bad-Wolf-Really-Isn-t-So-Big-and-Bad-by-Sara-Barnard.pdf
    • http://loaminoo.linkpc.net/1091095095090099/A-Heart-on-Hold-by-Sara-Barnard.pdf
    • http://loaminoo.linkpc.net/3097091092090090/A-Quiet-Kind-of-Thunder-by-Sara-Barnard.pdf
    • http://loaminoo.linkpc.net/1096097099093092/The-Orphanage-The-Saga-of-Indian-Em-ly-3-by-Sara-Barnard.pdf
    • http://loaminoo.linkpc.net/1093092092096091/A-Heart-on-Hold-An-Everlasting-Heart-1-by-Sara-Barnard.pdf
    • http://loaminoo.linkpc.net/8094093092094098/Lone-Wolf-FBI-K-9-1-by-Sara-Driscoll.pdf
    • http://loaminoo.linkpc.net/3090098094/Love-Me-Never-Lovely-Vicious-1-by-Sara-Wolf.pdf
    • http://loaminoo.linkpc.net/2098093090092093/Forget-Me-Always-Lovely-Vicious-2-by-Sara-Wolf.pdf
    • http://loaminoo.linkpc.net/1093094094099092/The-Education-of-Alice-Wells-by-Sara-Wolf.pdf
    • http://loaminoo.linkpc.net/4092096099091095/Find-Me-Their-Bones-Bring-Me-Their-Hearts-2-by-Sara-Wolf.pdf
    • http://loaminoo.linkpc.net/8091091094093093/A-Farming-Family-in-the-New-World-The-Barnard-Family-Saga-in-America-1679-2005-by-C-A-Coffey-Claudia-Barnard-Coffey.pdf
    • http://loaminoo.linkpc.net/4092097095096099/New-Scotia-Pack-Box-Set-Shield-Wolf-Wolf-Lover-Fire-Wolf-by-Victoria-Danann.pdf
    • http://loaminoo.linkpc.net/1098091094/Wolf-by-Wolf-Wolf-by-Wolf-1-by-Ryan-Graudin.pdf
    • http://loaminoo.linkpc.net/2094095090095097/Clear-the-Hurdles-Sara-Sara-3-by-Anna-Sellberg.pdf
    • http://loaminoo.linkpc.net/5098091092093092/Sara-s-Game-Sara-Winthrop-1-by-Ernie-Lindsey.pdf
    • http://loaminoo.linkpc.net/3098099099091096/Sara-s-Game-Sara-Winthrop-1-by-Ernie-Lindsey.pdf
    • http://loaminoo.linkpc.net/5098091094090095/Sara-s-Fear-Sara-Winthrop-3-by-Ernie-Lindsey.pdf
    • http://loaminoo.linkpc.net/1091091093090099091/Sara-and-the-Mystery-of-the-Thoroughbred-Sara-1-by-Anna-Sellberg.pdf
    • http://loaminoo.linkpc.net/1093091095099099/Night-of-the-Fox-Fox-3-by-Ashley-J-Barnard.pdf
    • http://loaminoo.linkpc.net/8091091096098091/A-Murder-in-Mayfair-by-Robert-Barnard.pdf