Malicious PDF — malware analysis report

Static analysis result for SHA-256 cf57a7b2de7c24cf…

MALICIOUS

PDF

31.0 KB Created: 2019-04-30 05:16:35 +01:00 Authoring application: mPDF 5.7
MD5: f1e789ea95d6f9ab7e1263a254786e42 SHA-1: 670f720ee604b3fe113db1b83efc39b5013a9b4e SHA-256: cf57a7b2de7c24cf975b2e08461b703f942bc98fd52f0b23100f542e7cc09c3f
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The PDF_LAUNCH heuristic also indicates that the document is configured to launch an action, likely to open these links. While the extracted URLs are currently marked as benign, the sheer volume and the nature of the PDF_SEO_LINK_FARM rule suggest a malicious intent, possibly for SEO manipulation or to distribute malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9966

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Launch action high PDF_LAUNCH
    PDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3098093099093093/The-Small-Business-Start-Up-Guide-A-Surefire-Blueprint-to-Successfully-Launch-Your-Own-Business-by-Hal-Root.pdf
    • http://loaminoo.linkpc.net/1090091090094098092/The-effectiveness-of-a-government-high-technology-small-business-program-within-a-small-business-incubator-A-case-study-in-government-university-and-business-collaboration-by-Anila-Nandkishore-Strahan.pdf
    • http://loaminoo.linkpc.net/5090094097092098/How-to-Make-Big-Money-in-Your-Own-Small-Business-Unexpected-Rules-Every-Small-Business-Owner-Needs-to-Know-by-Jeffrey-J-Fox.pdf
    • http://loaminoo.linkpc.net/9095090094097093/Start-And-Run-A-Delicatessen-Small-Business-Starters-Series-by-Deborah-Penrith.pdf
    • http://loaminoo.linkpc.net/7098095092099090/Jump-Start-Your-Business-Brain-Scientific-Ideas-and-Advice-That-Will-Immediately-Double-Your-Business-Success-Rate-by-Doug-Hall.pdf
    • http://loaminoo.linkpc.net/1090098095092097094/Offline-To-Online-Business-Manifesto-The-Step-By-Step-Blueprint-for-Strategically-Positioning-Your-Business-on-the-Internet-for-Mega-Profits-by-Ope-Banwo.pdf
    • http://loaminoo.linkpc.net/1091091094095098094/Small-Talk-for-Big-Business-Business-Conversation-f-r-bessere-Kontakte-by-Rene-Bosewitz.pdf
    • http://loaminoo.linkpc.net/1099097091094096/Accounting-for-the-Numberphobic-A-Survival-Guide-for-Small-Business-Owners-by-Dawn-Fotopulos.pdf
    • http://loaminoo.linkpc.net/8099099094090099/Money-for-Jam-2e-The-Essential-Guide-to-Starting-Your-Own-Small-Food-Business-2nd-edition-by-Oonagh-Monahan.pdf
    • http://loaminoo.linkpc.net/7092095097093097/How-You-Can-Start-and-Manage-Your-Own-Business-Complete-Step-By-Step-Guide-by-N-O-O-Ejiga.pdf
    • http://loaminoo.linkpc.net/1096091099092099/Building-Atlanta-How-I-Broke-Through-Segregation-to-Launch-a-Business-Empire-by-Herman-J-Russell.pdf
    • http://loaminoo.linkpc.net/4092091098097097/Entrepreneurship-The-Online-Money-Factory---Online-Business-Home-Business-amp-Business-Startup-by-Brian-Windley.pdf
    • http://loaminoo.linkpc.net/9095090095096093/How-to-Build-a-Delicatessen-Business-Special-Edition-The-Only-Book-You-Need-to-Launch-Grow-amp-Succeed-by-T-K-Johnson.pdf
    • http://loaminoo.linkpc.net/4099093091096090/Customer-LLC-The-Small-Business-Guide-to-Customer-Engagement-amp-Marketing-by-Hillary-Berman.pdf
    • http://loaminoo.linkpc.net/3093090090097090/Buying-A-Business-And-Making-It-Work-A-Step-By-Step-Guide-To-Purchasing-A-Business-And-Making-It-Successful-by-Mark-Blayney.pdf
    • http://loaminoo.linkpc.net/5091093099096/How-To-Start-a-Business-From-Home-by-Perry-Belcher.pdf
    • http://loaminoo.linkpc.net/2098094091099097/Launch-An-Internet-Millionaire-s-Secret-Formula-to-Sell-Almost-Anything-Online-Build-a-Business-You-Love-and-Live-the-Life-of-Your-Dreams-by-Jeff-Walker.pdf
    • http://loaminoo.linkpc.net/9094099094091093/Go-Negosyo-21-Steps-on-How-to-Start-Your-Own-Business-by-Dean-Pax-Lapid.pdf
    • http://loaminoo.linkpc.net/3097095098094091/Start-A-Home-Cleaning-Business-by-Amber-Richards.pdf
    • http://loaminoo.linkpc.net/9090097091097090/Clicks-in-E-Business-Perspektiven-Von-Start-Ups-Und-Etablierten-Konzernen-by-Max-J-Ringlstetter.pdf