Malicious PDF — malware analysis report

Static analysis result for SHA-256 d4ae4ce016841ccb…

MALICIOUS

PDF

14.4 KB Created: 2019-05-01 17:14:42 +01:00 Authoring application: mPDF 5.7
MD5: bf27e8144e77f060fe81097f27c2e6ea SHA-1: deb71d36de227aa4892efbc556a501dee7dcc83e SHA-256: d4ae4ce016841ccb8c935188d4d4b3f152870f1c0715b0bf0230093624f21566
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents, suggesting a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the sheer volume of links and the ML classification indicate a malicious intent to direct users to potentially harmful content. The primary attack pattern involves luring users through a deceptive document structure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/4097091096098/Katie-and-the-Cupcake-Cure-Cupcake-Diaries-1-by-Coco-Simon.pdf
    • http://loaminoo.linkpc.net/7097096091098/Alexis-The-Icing-on-the-Cupcake-Cupcake-Diaries-20-by-Coco-Simon.pdf
    • http://loaminoo.linkpc.net/5096094095091099/Katie-Starting-from-Scratch-Cupcake-Diaries-21-by-Coco-Simon.pdf
    • http://loaminoo.linkpc.net/5096094094095097/Mia-a-Matter-of-Taste-Cupcake-Diaries-14-by-Coco-Simon.pdf
    • http://loaminoo.linkpc.net/5096094095091095/Emma-Sugar-and-Spice-and-Everything-Nice-Cupcake-Diaries-15-by-Coco-Simon.pdf
    • http://loaminoo.linkpc.net/2091099099094092/Sweet-on-You-The-Cupcake-Diaries-1-by-Darlene-Panzera.pdf
    • http://loaminoo.linkpc.net/4097096096090092/Sprinkled-with-Kisses-The-Cupcake-Diaries-5-by-Darlene-Panzera.pdf
    • http://loaminoo.linkpc.net/2096094099092093/How-to-Eat-a-Cupcake-by-Meg-Donohue.pdf
    • http://loaminoo.linkpc.net/2098098093099092/Cupcake-Girl-by-Mei-Writes.pdf
    • http://loaminoo.linkpc.net/3098099091090090/The-Cupcake-Dilemma-by-Jennifer-Rodewald.pdf
    • http://loaminoo.linkpc.net/3092093099098091/The-Cupcake-Queen-by-Heather-Hepler.pdf
    • http://loaminoo.linkpc.net/1099095097091094/Rebel-with-a-Cupcake-by-Anna-Mainwaring.pdf
    • http://loaminoo.linkpc.net/2098090095091096/Cupcake-Cyd-Charisse-3-by-Rachel-Cohn.pdf
    • http://loaminoo.linkpc.net/2091096094093091/Babycakes-Cupcake-Club-3-by-Donna-Kauffman.pdf
    • http://loaminoo.linkpc.net/3091095097092095/Recipe-for-Trouble-The-Cupcake-Club-2-by-Sheryl-Berk.pdf
    • http://loaminoo.linkpc.net/6095092093099098/Cupcake-The-little-Sorcerer-Who-Eats-her-Boogers-by-Marie-Perrot.pdf
    • http://loaminoo.linkpc.net/1098093099091098/Don-t-Call-Me-Cupcake-The-Holloway-Girls-1-by-Tara-Sheets.pdf
    • http://loaminoo.linkpc.net/4093093093099098/In-the-Mood-for-Love-Cupcake-Lovers-4-by-Beth-Ciotta.pdf
    • http://loaminoo.linkpc.net/4096095097097092/The-Cupcake-Cowboy-Lone-Star-Sweets-1-by-Lissa-Matthews.pdf
    • http://loaminoo.linkpc.net/4099091090090092/Chai-Cupcake-Killer-INNcredibly-Sweet-4-by-Summer-Prescott.pdf