Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9d4069ed05ab2d7…

MALICIOUS

PDF

14.7 KB Created: 2019-05-04 13:58:34 +01:00 Authoring application: mPDF 5.7
MD5: 349b80cd8f0262f8e482a544edc1c0c6 SHA-1: 46aa399ef67390c40b4d263927297a9e49259dc9 SHA-256: d9d4069ed05ab2d7ddc3a4b8a0ea8e00c35e977aa8c5210b350c8ba1578a97bd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The ML classifier also flagged the PDF as malicious with high confidence. While no scripts were extracted, the sheer volume of links suggests a malicious intent, possibly to direct users to phishing sites or to distribute further malware. The URLs themselves appear to be part of a link farm, with many pointing to book titles, which could be a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7091094096095090/My-Sister-s-Continent-by-Gina-Frangello.pdf
    • http://loaminoo.linkpc.net/1099092094092091/A-Kind-of-Truth-A-Kind-of-Stories-1-by-Lane-Hayes.pdf
    • http://loaminoo.linkpc.net/6090096098095090/Wanting-Mor-by-Rukhsana-Khan.pdf
    • http://loaminoo.linkpc.net/4091099099099093/Wanting-It-by-Scarlet-Wilder.pdf
    • http://loaminoo.linkpc.net/4090095095096091/The-Wanting-The-Waiting-3-by-Elizabeth-Burgess.pdf
    • http://loaminoo.linkpc.net/1091098094092098/Wanting-More-Mitchell-Family-5-by-Jennifer-Foor.pdf
    • http://loaminoo.linkpc.net/1091091099096095094/Wanting-Jordie-Darkfall-Mountain-Pack-7-by-Fel-Fern.pdf
    • http://loaminoo.linkpc.net/4098091099090094/Wanting-PAVAD-FBI-Romantic-Suspense-2-by-Calle-J-Brookes.pdf
    • http://loaminoo.linkpc.net/2097099091099093/Wanting-You-Book-One-of-the-Broken-Road-Series-by-Becca-Siller.pdf
    • http://loaminoo.linkpc.net/1094096091097097/The-Girl-Who-Forgot-The-Butterflies-A-gripping-emotional-page-turner-that-will-keep-you-wanting-more-by-Marsha-Heather-Graham.pdf
    • http://loaminoo.linkpc.net/2090096097096096/Right-Kind-of-Mistake-Right-Kind-of-Mistake-1-by-Rebecca-Thomas.pdf
    • http://loaminoo.linkpc.net/2090090090091093/Just-Me-in-the-Tub-by-Gina-Mayer.pdf
    • http://loaminoo.linkpc.net/1097095090099093/Wax-by-Gina-Damico.pdf
    • http://loaminoo.linkpc.net/1092091097092096/What-You-Wish-For-by-Gina-Wynn.pdf
    • http://loaminoo.linkpc.net/1090096099094099/Brightest-Kind-of-Darkness-Brightest-Kind-of-Darkness-1-by-P-T-Michelle.pdf
    • http://loaminoo.linkpc.net/1090099095093097/Brightest-Kind-of-Darkness-Brightest-Kind-of-Darkness-1-by-P-T-Michelle.pdf
    • http://loaminoo.linkpc.net/4099098091099091/Ignis-by-Gina-Wilson.pdf
    • http://loaminoo.linkpc.net/5090090097094096/Forget-Me-Never-by-Gina-Blaxill.pdf
    • http://loaminoo.linkpc.net/4092095097093099/Just-Between-Series-by-Gina-L-Dartt.pdf
    • http://loaminoo.linkpc.net/2099090092096/Eternally-Yours-by-Gina-Ardito.pdf
    • http://loaminoo.linkpc.net/2090096097096096/Right-Kind-of-Mistake-Right-Kind-of-