Malicious PDF — malware analysis report

Static analysis result for SHA-256 da7e5a066b36e8ab…

MALICIOUS

PDF

21.2 KB Created: 2019-05-02 07:58:22 +01:00 Authoring application: mPDF 5.7
MD5: c315d56b808a1719903a3bc36a8e3fdb SHA-1: 992e9cccf8194e5de046d0607bd5ae5eef08b636 SHA-256: da7e5a066b36e8ab680cbfda9cf5065e18b8b2c64073adc8dd95cf933ebe498f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS classifier also flagged this file with high confidence. The URLs point to a domain that appears to be used for hosting numerous book-related PDFs, suggesting a potential SEO manipulation or content distribution scheme. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092095091095097/A-Wilder-Rose-Rose-Wilder-Lane-Laura-Ingalls-Wilder-and-Their-Little-Houses-by-Susan-Wittig-Albert.pdf
    • http://loaminoo.linkpc.net/1090096090099099091/The-Rediscovered-Writings-of-Rose-Wilder-Lane-Literary-Journalist-by-Amy-Mattson-Lauters.pdf
    • http://loaminoo.linkpc.net/1091093096099091092/Dorothy-Thompson-and-Rose-Wilder-Lane-Forty-Years-of-Friendship-Letters-1921-1960-by-William-Holtz.pdf
    • http://loaminoo.linkpc.net/2097094094091094/American-Individualism-by-Herbert-Hoover.pdf
    • http://loaminoo.linkpc.net/9092093099098096/Herbert-Hoover-The-American-Presidents-31-by-William-E-Leuchtenburg.pdf
    • http://loaminoo.linkpc.net/9092094091093098/An-Uncommon-Man-The-Triumph-of-Herbert-Hoover-by-Richard-Norton-Smith.pdf
    • http://loaminoo.linkpc.net/1095094094096095/Freedom-Betrayed-Herbert-Hoover-s-Secret-History-of-the-Second-World-War-and-Its-Aftermath-by-George-H-Nash.pdf
    • http://loaminoo.linkpc.net/9092093099095090/Colossus-Hoover-Dam-and-the-Making-of-the-American-Century-by-Michael-A-Hiltzik.pdf
    • http://loaminoo.linkpc.net/7099099099096/A-Wilder-Rose-by-Susan-Wittig-Albert.pdf
    • http://loaminoo.linkpc.net/2094096097096098/Rose-s-Story-The-Girls-of-Lighthouse-Lane-2-by-Thomas-Kinkade.pdf
    • http://loaminoo.linkpc.net/7097093094096093/Making-a-Rose-Garden-Loth-by-Ethne-Clarke.pdf
    • http://loaminoo.linkpc.net/5093092096095094/Mining-For-Treasure-Herbert-s-Family-Vacation-Herbert-Books-Book-2-by-Carol-Eyster.pdf
    • http://loaminoo.linkpc.net/7091097092091/Bridget-Wilder-Spy-in-Training-Bridget-Wilder-Series-by-Jonathan-Bernstein.pdf
    • http://loaminoo.linkpc.net/1093098091097099/West-from-Home-Letters-of-Laura-Ingalls-Wilder-San-Francisco-1915-Little-House-11-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/1096099094095099/A-Little-House-Traveler-Writings-from-Laura-Ingalls-Wilder-s-Journeys-Across-America-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/9090096092097091/Die-Ara-Haslauer-Salzburg-in-Den-Siebziger-Und-Achtziger-Jahren-Herausgegeben-Von-Herbert-Dachs-Ernst-Hanisch-Roland-Floimair-Und-Franz-Schausberger-by-Herbert-Dachs.pdf
    • http://loaminoo.linkpc.net/1097091095092092/Making-Her-Man-Open-Up-Making-Her-Man---A-Femdom-Series-Book-3-by-Simone-Dottie.pdf
    • http://loaminoo.linkpc.net/1097091095091090/Making-Her-Man-Obey-Making-Her-Man---A-Femdom-Series-Book-2-by-Simone-Dottie.pdf
    • http://loaminoo.linkpc.net/4094091099093095/Country-Soul-Making-Music-and-Making-Race-in-the-American-South-by-Charles-L-Hughes.pdf
    • http://loaminoo.linkpc.net/2096092098095097/Making-Plans-Making-Memories-Reprisal-Volume-1-by-Sam-Lang.pdf
    • http://loaminoo.linkpc.net/9092094091093098/An-Uncommon-Man-The-Triumph-of-Herbert-Hoover-b