Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb5eccbf8239d3a0…

MALICIOUS

PDF

15.7 KB Created: 2019-05-06 16:34:48 +01:00 Authoring application: mPDF 5.7
MD5: 38b132e1881c52ecfb3288d0d72d3bd4 SHA-1: c5a22089b52bdbc81cd2aeef9708913fea31e1f7 SHA-256: cb5eccbf8239d3a0ac48356b9a8db09b37ccd4b902194204a44f8fa1a429e2ab
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified as a PDF SEO link farm, which is a common technique for distributing malicious content or manipulating search engine results. The primary attack pattern involves directing users to external, potentially harmful, PDF documents via these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096097096097090/44-Scotland-Street-44-Scotland-Street-1-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3094091090092093/44-Scotland-Street-44-Scotland-Street-1-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/9096094092099099/T-r-an-T-r-in-der-44-Scotland-Street-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3093091093095097/Espresso-Tales-44-Scotland-Street-2-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3096091098098098/The-Bertie-Project-44-Scotland-Street-11-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/2098095093093096/The-Revolving-Door-of-Life-44-Scotland-Street-10-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/2099093093095091/Echoes-of-Scotland-Street-On-Dublin-Street-5-by-Samantha-Young.pdf
    • http://loaminoo.linkpc.net/8097091094091/Echoes-of-Scotland-Street-On-Dublin-Street-5-by-Samantha-Young.pdf
    • http://loaminoo.linkpc.net/1091096090096093091/A-Work-of-Beauty-Alexander-McCall-Smith-s-Edinburgh-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/8092091093091093/Dumbarton-Burgh-Records-1627-1746-by-Dumbarton-Scotland-Dumbart-Scotland.pdf
    • http://loaminoo.linkpc.net/3093091095094092/One-City-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7090094090092092/Les-larmes-de-la-girafe-2-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7099097091091092/Amori-in-viaggio-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/3093094097096098/Tears-of-the-Giraffe-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/6098090098097090/Akimbo-and-the-Elephants-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7093098093098096/The-Joke-Machine-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/8098099092090099/Voices-From-The-Street-An-Ethnography-Of-India-s-Street-Children-A-Case-Study-Of-Delhi-by-Lori-McFadyen.pdf
    • http://loaminoo.linkpc.net/3099090098096095/Morality-For-Beautiful-Girls-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/2091097094099090/The-Dog-who-Came-in-from-the-Cold-Corduroy-Mansions-2-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/1098096098098099/La-s-Orchestra-Saves-the-World-by-Alexander-McCall-Smith.pdf
    • http://loaminoo.linkpc.net/7090094090092092/Les-larmes-de-la-girafe-2-by-Al