Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca760e4814c5558f…

MALICIOUS

PDF

23.2 KB Created: 2019-05-03 05:07:57 +01:00 Authoring application: mPDF 5.7
MD5: c5fc84055348210f623abe3f245932fb SHA-1: d2b84e41b7b81c675e2b52f30a5cd813cb0209a3 SHA-256: ca760e4814c5558f3971b432d48ae9d47725c5632bdd4f261845e04be8f57ade
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to manipulate search engine results or distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3090093096091097/Why-a-Duck-Visual-and-Verbal-Gems-from-the-Marx-Brothers-Movies-by-Richard-J-Anobile.pdf
    • http://loaminoo.linkpc.net/3090094095097090/Hail-Hail-Euphoria-Presenting-the-Marx-Brothers-in-Duck-Soup-the-Greatest-War-Movie-Ever-Made-by-Roy-Blount-Jr-.pdf
    • http://loaminoo.linkpc.net/6096094097091091/Outland-The-movie-novel-based-upon-the-screen-play-by-Peter-Hyams-by-Richard-J-Hyams-Peter-Anobile.pdf
    • http://loaminoo.linkpc.net/2095097098092099/Doing-Philosophy-at-the-Movies-by-Richard-Allen-Gilmore.pdf
    • http://loaminoo.linkpc.net/2098097097098097/Movies-In-Fifteen-Minutes-The-Ten-Biggest-Movies-Ever-For-People-Who-Can-t-Be-Bothered-by-Cleolinda-Jones.pdf
    • http://loaminoo.linkpc.net/3095092096099096/Duck-Duck-Ghost-Hellsinger-2-by-Rhys-Ford.pdf
    • http://loaminoo.linkpc.net/3094093096090091/Duck-Duck-Wally-A-Novel-by-Gabe-Rotter.pdf
    • http://loaminoo.linkpc.net/3096092091091096/Duck-Duck-Moose-by-Joy-Heyer.pdf
    • http://loaminoo.linkpc.net/2096093098091097/Duck-Duck-Goose-by-Tad-Hills.pdf
    • http://loaminoo.linkpc.net/1090090092090090095/Visual-Finance-The-One-Page-Visual-Model-to-Understand-Financial-Statements-and-Make-Better-Business-Decisions-by-Georgi-Tsvetanov.pdf
    • http://loaminoo.linkpc.net/1091097094099095097/Die-Synthese-von-materialistischer-Geschichtsphilosophie-und-konomischer-Theorie-in-Marx-Fr-hschriften-Das-Elend-der-Philosophie-und-Brief-an-Annenkow-Das-Fr-hwerk-von-Karl-Marx-by-Martin-Gliemann.pdf
    • http://loaminoo.linkpc.net/4095098097090097/The-Scent-of-My-Childhood-Gems-Eclair-Morton-Book-1-by-Gems-Eclair-Morton.pdf
    • http://loaminoo.linkpc.net/1090092092097091090/The-Power-of-Gems-Stones-The-Power-of-Gems-Stones-Meanings-by-Akila-M-Ramses.pdf
    • http://loaminoo.linkpc.net/4093091095097/The-Marx-Engels-Reader-by-Karl-Marx.pdf
    • http://loaminoo.linkpc.net/1091098099095096095/Jenseits-der-Illusionen-Die-Bedeutung-von-Marx-und-Freud-Beyond-the-Chains-of-Illusion-My-Encounter-with-Marx-and-Freud-by-Erich-Fromm.pdf
    • http://loaminoo.linkpc.net/7094094090092094/The-Eighteenth-Brumaire-of-Louis-Bonaparte-One-of-Karl-Marx-Most-Profound-and-Most-Brilliant-Monographs-by-Karl-Marx.pdf
    • http://loaminoo.linkpc.net/1095092095094091/The-James-Boys-A-Novel-Account-of-Four-Desperate-Brothers-by-Richard-Liebmann-Smith.pdf
    • http://loaminoo.linkpc.net/8090099093092097/A-Cup-of-Verbal-Tea-by-Shaine-Singer.pdf
    • http://loaminoo.linkpc.net/4097094098094097/Verbal-Behavior-by-B-F-Skinner.pdf
    • http://loaminoo.linkpc.net/9096091093099097/Love-and-Let-Lust-Verbal-Nut-Bust-1-by-HoBs.pdf
    • http://loaminoo.linkpc.net/2098097097098097/Movies-In-Fifteen-Minutes-The-Ten-Biggest-Movies-Ever-For-People-Who-Can-t-Be-Bothered-by-Cleolinda-