Malicious PDF — malware analysis report

Static analysis result for SHA-256 cefaef7eb061627f…

MALICIOUS

PDF

17.6 KB Created: 2019-05-02 01:40:47 +01:00 Authoring application: mPDF 5.7
MD5: d1acbe0966f5672303a98b9a67f1a41e SHA-1: bb007ee9ef1f9efc797464181ef284515d230dca SHA-256: cefaef7eb061627ff258f5e384f4e74d788ed7f0c7d6388359197764c2e7b8e4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly flagged this PDF as malicious, and the heuristic analysis identified it as a link farm. While no scripts were extracted, the sheer volume of links and the ML score indicate a high likelihood of malicious intent, possibly to redirect users to phishing sites or download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2096095093097090/Family-Honor-Sunny-Randall-1-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/3099095090096094/Love-and-Honor-by-Randall-Wallace.pdf
    • http://loaminoo.linkpc.net/4092091094091095/Living-on-the-Sunny-Side-A-Memoir-by-Sunny-Deuber.pdf
    • http://loaminoo.linkpc.net/2092096092091091/Parker-s-Wine-Buyer-s-Guide-The-Complete-Easy-To-Use-Reference-on-Recent-Vintages-Prices-and-Ratings-for-More-Than-8-000-Wines-from-All-the-Major-Wine-Regions-by-Robert-M-Parker-Jr-.pdf
    • http://loaminoo.linkpc.net/1090091094096095095/History-of-Corporate-Governance-Around-the-World-A-Family-Business-Groups-to-Professional-Managers-by-Randall-K-Morck.pdf
    • http://loaminoo.linkpc.net/4097099099099/Reconciliation-Road-A-Family-Odyssey-of-War-and-Honor-by-John-Douglas-Marshall.pdf
    • http://loaminoo.linkpc.net/1091095095094099090/Blood-and-Honor-Inside-the-Scarfo-Mob--The-Mafia-s-Most-Violent-Family-by-George-Anastasia.pdf
    • http://loaminoo.linkpc.net/2098099097097098/Kiss-of-Fire-St-James-Family-Book-2-by-Lavender-Parker.pdf
    • http://loaminoo.linkpc.net/7093091093094092/Murder-of-Honor-A-by-Robert-Andrews.pdf
    • http://loaminoo.linkpc.net/5092091097099091/Frontier-Blood-The-Saga-of-the-Parker-Family-by-Jo-Ella-Powell-Exley.pdf
    • http://loaminoo.linkpc.net/3096091099098092/Playmates-Spenser-16-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/1090094099090092092/Miese-Gesch-fte-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/3095097090095091/Perchance-to-Dream-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/9097091095090097/A-Year-at-the-Races-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/3099091093091090/Playmates-Spenser-16-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/4091091090096095/Potshot-Spenser-28-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/2095096094099094/Mommy-Diagnostics-The-Naturally-Healthy-Family-s-Guide-to-Herbs-and-Whole-Foods-for-Health-by-Shonda-Parker.pdf
    • http://loaminoo.linkpc.net/4093096092098/The-Widening-Gyre-Spenser-10-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/4099091098094097/The-Judas-Goat-Spenser-5-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/2093093092094096/Early-Autumn-Spenser-7-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/4097099099099/Reconciliation-Road-A-Fami