Malicious PDF — malware analysis report

Static analysis result for SHA-256 cf3d14cb87a3425c…

MALICIOUS

PDF

19.2 KB Created: 2019-05-02 05:17:06 +01:00 Authoring application: mPDF 5.7
MD5: e4077c1644c9d96806fb120cd04e8b37 SHA-1: 4c8abb02a607d9870136a9a225817a49f1bd4c7d SHA-256: cf3d14cb87a3425c3a74cd8770469ae6d551a81f55cf733ab0787df959fee4fc
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs point to benign-looking book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely for SEO spam or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7098093097091097/When-Trauma-Survivors-Return-to-Work-Understanding-Emotional-Recovery-by-Barbara-Barski-Carrow.pdf
    • http://loaminoo.linkpc.net/6094094090095098/Healing-Developmental-Trauma-How-Early-Trauma-Affects-Self-Regulation-Self-Image-and-the-Capacity-for-Relationship-by-Laurence-Heller.pdf
    • http://loaminoo.linkpc.net/8093094090094/The-Queen-s-Gamble-Thornleigh-4-by-Barbara-Kyle.pdf
    • http://loaminoo.linkpc.net/4091093095098099/The-Queen-s-Gamble-Thornleigh-4-by-Barbara-Kyle.pdf
    • http://loaminoo.linkpc.net/4092098092095097/Queen-of-the-Courtesans-Fanny-Murray-by-Barbara-White.pdf
    • http://loaminoo.linkpc.net/4099097097090097/Knight-of-the-Demon-Queen-Winterlands-3-by-Barbara-Hambly.pdf
    • http://loaminoo.linkpc.net/1092099099097098/The-Reclamation-Of-A-Queen-Guinevere-In-Modern-Fantasy-by-Barbara-Ann-Gordon-Wise.pdf
    • http://loaminoo.linkpc.net/1090095094099098/Trauma-by-Patrick-McGrath.pdf
    • http://loaminoo.linkpc.net/2093090094096097/Warrior-Queen-The-Story-of-Boudica-Celtic-Queen-by-Alan-Gold.pdf
    • http://loaminoo.linkpc.net/1097098097097093/Counting-One-s-Blessings-The-Selected-Letters-of-Queen-Elizabeth-the-Queen-Mother-by-William-Shawcross.pdf
    • http://loaminoo.linkpc.net/4097096098095095/The-Lady-Queen-The-Notorious-Reign-of-Joanna-I-Queen-of-Naples-Jerusalem-and-Sicily-by-Nancy-Goldstone.pdf
    • http://loaminoo.linkpc.net/3094092096093092/The-Idylls-of-the-Queen-A-Tale-of-Queen-Guenevere-by-Phyllis-Ann-Karr.pdf
    • http://loaminoo.linkpc.net/2091090092090091/Queen-Takes-Knights-Their-Vampire-Queen-1-by-Joely-Sue-Burkhart.pdf
    • http://loaminoo.linkpc.net/1095090099091090/Queen-s-Own-Fool-A-Novel-of-Mary-Queen-of-Scots-by-Jane-Yolen.pdf
    • http://loaminoo.linkpc.net/1090094095090097/The-Unruly-Queen-The-Life-of-Queen-Caroline-by-Flora-Fraser.pdf
    • http://loaminoo.linkpc.net/2094099093090/The-Summer-Queen-The-Snow-Queen-Cycle-3-by-Joan-D-Vinge.pdf
    • http://loaminoo.linkpc.net/2094092097091099/The-Queen-of-Attolia-The-Queen-s-Thief-2-by-Megan-Whalen-Turner.pdf
    • http://loaminoo.linkpc.net/7099099091091099/Trauma-Surgery-by-Kirby-I-Bland.pdf
    • http://loaminoo.linkpc.net/1090098094096094097/Eifel-Trauma-by-Peter-Splitt.pdf
    • http://loaminoo.linkpc.net/4090093095095093/Five-Gold-Rings-A-Royal-Wedding-Souvenir-Album-from-Queen-Victoria-to-Queen-Elizabeth-II-by-Jane-Roberts.pdf