Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc1db94938192af0…

MALICIOUS

PDF

17.2 KB Created: 2019-05-02 05:45:54 +01:00 Authoring application: mPDF 5.7
MD5: ae91145c1368c6210d7d4e9320bc0fcb SHA-1: 3884173d925d3314e924d1ca8d74f9ce1b1be75e SHA-256: cc1db94938192af02d4a7b18d3240fde3bea53d7fefa415490a3436dc2c8361d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDFs, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malware. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097099092091098/The-Alchemist-of-Souls-Night-s-Masque-1-by-Anne-Lyle.pdf
    • http://loaminoo.linkpc.net/2098090093097097/The-Prince-of-Lies-Night-s-Masque-3-by-Anne-Lyle.pdf
    • http://loaminoo.linkpc.net/4096099094090/The-Neutronium-Alchemist-Night-s-Dawn-2-by-Peter-F-Hamilton.pdf
    • http://loaminoo.linkpc.net/6098093096095093/Fullmetal-Alchemist-The-Abducted-Alchemist-Fullmetal-Alchemist-2-by-Makoto-Inoue.pdf
    • http://loaminoo.linkpc.net/3091094091094098/The-Doomsday-Machine-A-Further-Astonishing-Adventure-of-Horatio-Lyle-Horatio-Lyle-3-by-Catherine-Webb.pdf
    • http://loaminoo.linkpc.net/8099090092091/The-Night-s-Dawn-Trilogy-The-Reality-Dysfunction-The-Neutronium-Alchemist-and-The-Naked-God-by-Peter-F-Hamilton.pdf
    • http://loaminoo.linkpc.net/6091091091099095/The-Alchemist-The-Alchemist-Greatest-Life-Lessons-and-Best-Quotes-Paulo-Coelho-by-Karen-Harris.pdf
    • http://loaminoo.linkpc.net/4093095098093097/The-Alchemist-s-Code-The-Alchemist-2-by-Dave-Duncan.pdf
    • http://loaminoo.linkpc.net/2098097095099095/The-Alchemist-s-Code-The-Alchemist-2-by-Dave-Duncan.pdf
    • http://loaminoo.linkpc.net/3095099095099093/Our-Souls-at-Night-by-Kent-Haruf.pdf
    • http://loaminoo.linkpc.net/2093092090096097/All-Souls-Night-by-Hugh-Walpole.pdf
    • http://loaminoo.linkpc.net/5090095092092092/Our-Souls-at-Night-by-Kent-Haruf.pdf
    • http://loaminoo.linkpc.net/4092097096092090/Soul-Chase-Dark-Souls-3-by-Anne-Hope.pdf
    • http://loaminoo.linkpc.net/2090095094098098/All-Souls-Night-Blood-Ties-4-by-Jennifer-Armintrout.pdf
    • http://loaminoo.linkpc.net/8097096099099/Shadow-of-Night-All-Souls-Trilogy-2-by-Deborah-Harkness.pdf
    • http://loaminoo.linkpc.net/4094094094095097/Investigations-of-the-Reverend-Lyle-Thorne-Reverend-Lyle-Thorne-Mysteries-1-by-Ray-Moore.pdf
    • http://loaminoo.linkpc.net/7097099091090/Fullmetal-Alchemist-The-Land-of-Sand-Fullmetal-Alchemist-1-by-Makoto-Inoue.pdf
    • http://loaminoo.linkpc.net/6098093096095096/Fullmetal-Alchemist-To-Each-His-Own-Bonds-Fullmetal-Alchemist-5-by-Makoto-Inoue.pdf
    • http://loaminoo.linkpc.net/1094093092095095/Fullmetal-Alchemist-Vol-10-Fullmetal-Alchemist-10-by-Hiromu-Arakawa.pdf
    • http://loaminoo.linkpc.net/1094093094098092/Fullmetal-Alchemist-Vol-9-Fullmetal-Alchemist-9-by-Hiromu-Arakawa.pdf
    • http://loaminoo.linkpc.net/6091091091099095/The-Alchemist-The-Alchemist-Greatest-Life-Lessons