Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb90bb85497a8ad3…

MALICIOUS

PDF

18.5 KB Created: 2019-04-30 04:42:09 +01:00 Authoring application: mPDF 5.7
MD5: f124fb3d0b3f1498e4276b6643badf0f SHA-1: 0529b11c55464f4f9d1f5f27db10360e24c42f65 SHA-256: cb90bb85497a8ad37259e7044a53e6e65d6a093b0f289af6ba9c6aa1a9b15e2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The primary heuristic indicates a 'PDF_SEO_LINK_FARM', suggesting the document is designed to manipulate search engine results or distribute content via numerous links. While no scripts were extracted, the presence of many links, some of which are to potentially benign-looking book titles, suggests a lure or redirection mechanism. The attack pattern is likely related to distributing further malicious content or SEO abuse.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091099090091095093/Santa-Claus-Doesn-t-Mop-Floors-The-Adventures-of-the-Bailey-School-Kids-3-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/6097095099097098/Frankenstein-Doesn-t-Plant-Petunias-The-Adventures-Of-The-Bailey-School-Kids-6-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/2094091091099097/Cupid-Doesn-t-Flip-Hamburgers-The-Adventures-of-the-Bailey-School-Kids-12-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/2098097091093097/Frankenstein-Doesn-t-Slam-Hockey-Pucks-The-Adventures-of-the-Bailey-School-Kids-34-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/4097094093092093/Angels-Don-t-Know-Karate-The-Adventures-Of-The-Bailey-School-Kids-23-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/1098090099092093/Gremlins-Don-t-Chew-Bubble-Gum-Adventures-Of-The-Bailey-School-Kids-13-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/4092095093095092/Ghosts-Don-t-Eat-Potato-Chips-The-Adventures-of-the-Bailey-School-Kids-5-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/4090096095092099/Zombies-Don-t-Play-Soccer-The-Adventures-of-the-Bailey-School-Kids-15-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/2098099097090098/Elves-Don-t-Wear-Hard-Hats-The-Adventures-of-the-Bailey-School-Kids-17-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/2099098099098097/The-Life-and-Adventures-of-Santa-Claus-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/1093098091092093/The-Life-and-Adventures-of-Santa-Claus-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/6093093096097095/The-Polar-Bear-Express-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/3090093093097092/Trouble-at-Trident-Academy-by-Debbie-Dadey.pdf
    • http://loaminoo.linkpc.net/8091092097099093/Santa-Claus-Exposed-by-Guy-Incognito.pdf
    • http://loaminoo.linkpc.net/1091099090091099098/Here-Comes-Santa-Claus-by-Gene-Autry.pdf
    • http://loaminoo.linkpc.net/1096099093098095/Is-there-a-Santa-Claus-by-Jacob-A-Riis.pdf
    • http://loaminoo.linkpc.net/5090092092095091/I-Believe-in-Santa-Claus-by-Diane-Adamson.pdf
    • http://loaminoo.linkpc.net/9091098099092091/Carving-Santa-and-Mrs-Claus-by-Ken-Blomquist.pdf
    • http://loaminoo.linkpc.net/6093091090090/A-Kidnapped-Santa-Claus-by-L-Frank-Baum.pdf
    • http://loaminoo.linkpc.net/1091099090090099092/A-Kidnapped-Santa-Claus-by-L-Frank-Baum.pdf