Malicious PDF — malware analysis report

Static analysis result for SHA-256 c359d84e9bba00cd…

MALICIOUS

PDF

15.3 KB Created: 2019-05-02 01:28:30 +01:00 Authoring application: mPDF 5.7
MD5: e4dde1e2def5eea8904c28a7d6435b8f SHA-1: cfa3647869506d8cc07efa20d318c689aa2f2940 SHA-256: c359d84e9bba00cd8bf20426da30cda0a1176a3bbd63628151ed57354f8849af
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. While no scripts were extracted, the sheer volume of links and the ML classification indicate a malicious intent, likely to direct users to malicious sites or to manipulate search engine rankings.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.n
    • http://loaminoo.linkpc.net/8097092095095099/The-Rating-Agencies-and-Their-Credit-Ratings-What-They-Are-How-They-Work-and-Why-They-Are-Relevant-by-Herwig-Langohr.pdf
    • http://loaminoo.linkpc.net/2095093092092096/Glenn-Hates-Books-Vol-1-Brutally-Honest-Book-Reviews-by-Glenn-Conley.pdf
    • http://loaminoo.linkpc.net/2096091099090093/Life-Prison-Life-Prison-Mercy-s-Prisoner-1-by-Dusk-Peterson.pdf
    • http://loaminoo.linkpc.net/4094097094096097/Glenn-Hughes-The-Autobiography---From-Deep-Purple-to-Black-Country-Communion-by-Glenn-Hughes.pdf
    • http://loaminoo.linkpc.net/3090092095096091/Release-by-Patrick-Ness.pdf
    • http://loaminoo.linkpc.net/4099097093094099/Wild-Release-by-Amy-Ruttan.pdf
    • http://loaminoo.linkpc.net/1095092091098091/Release-by-Beth-Kery.pdf
    • http://loaminoo.linkpc.net/3090097092092094/Release-by-Nicole-Hadaway.pdf
    • http://loaminoo.linkpc.net/3096090093099094/Release-The-Protector-3-by-M-R-Merrick.pdf
    • http://loaminoo.linkpc.net/1095097095091094/The-Release-The-Prey-3-by-Tom-Isbell.pdf
    • http://loaminoo.linkpc.net/2091090090097091/Release-Davlova-1-by-A-M-Sexton.pdf
    • http://loaminoo.linkpc.net/4096097099099/Release-Me-Stark-Trilogy-1-by-J-Kenner.pdf
    • http://loaminoo.linkpc.net/1097090098095093/Release-Submerged-Sun-3-by-Vanessa-Garden.pdf
    • http://loaminoo.linkpc.net/2092094099/Release-The-Walker-Brothers-1-by-J-S-Scott.pdf
    • http://loaminoo.linkpc.net/1091090093096093/The-Release-Virulent-1-by-Shelbi-Wescott.pdf
    • http://loaminoo.linkpc.net/4098096099094090/Release-Me-Control-2-by-Shanora-Williams.pdf
    • http://loaminoo.linkpc.net/1094095097095098/VIP-Rock-amp-Release-Act-1-by-Riley-Edgewood.pdf
    • http://loaminoo.linkpc.net/1094097098098090/Release-Fire-on-Ice-5-by-Brenda-Rothert.pdf
    • http://loaminoo.linkpc.net/3090092093095091/Release-the-Stars-by-Harper-Bliss.pdf
    • http://loaminoo.linkpc.net/7090099096092/Breathe-and-Release-by-Katherine-Hayton.pdf