Malicious PDF — malware analysis report

Static analysis result for SHA-256 dda1b7dc421df17f…

MALICIOUS

PDF

23.5 KB Created: 2019-04-30 04:13:02 +01:00 Authoring application: mPDF 5.7
MD5: fa28c0d0870e82fffa32fde7a20950f0 SHA-1: 81418670b9c496ae9adb9bfa57ed2cedb4a378a6 SHA-256: dda1b7dc421df17fd9a122ea425f54c667ac90cf58581addb6347183bc148aa5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs point to benign-looking book titles, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8096090096092096/Why-Do-Ice-Cubes-Float-Questions-and-Answers-about-the-Science-of-Everyday-Materials-by-Thomas-Canavan-Jr-.pdf
    • http://loaminoo.linkpc.net/8096090096092094/Does-It-Really-Rain-Frogs-Questions-and-Answers-about-Planet-Earth-by-Thomas-Canavan-Jr-.pdf
    • http://loaminoo.linkpc.net/8096090096092095/Why-Are-Black-Holes-Black-Questions-and-Answers-about-Space-by-Thomas-Canavan-Jr-.pdf
    • http://loaminoo.linkpc.net/8097094090097091/What-Einstein-Told-His-Barber-More-Scientific-Answers-to-Everyday-Questions-by-Robert-L-Wolke.pdf
    • http://loaminoo.linkpc.net/2099097099095098/Mystery-and-Crime-The-New-York-Public-Library-Book-of-Answers-Intriguing-and-Entertaining-Questions-and-Answers-About-the-Who-s-Who-and-Whats-s-by-Jay-Pearsall.pdf
    • http://loaminoo.linkpc.net/1090099092099097093/Qualitative-Inquiry-in-Everyday-Life-Working-with-Everyday-Life-Materials-by-Svend-Brinkmann.pdf
    • http://loaminoo.linkpc.net/1091092096099097090/New-and-Advanced-Materials-Selected-Papers-2v-International-Conference-on-Manufacturing-Science-and-Engineering-2011-Guilin-China-Advanced-Materials-Research-V-197-8-by-Huaiying-Zhou.pdf
    • http://loaminoo.linkpc.net/9090091098/Brief-Answers-to-the-Big-Questions-by-Stephen-Hawking.pdf
    • http://loaminoo.linkpc.net/3094094095097097/Questions-and-Answers-about-Weather-by-M-Jean-Craig.pdf
    • http://loaminoo.linkpc.net/6099099094092097/Essentials-of-NLP-150-Questions-amp-Answers-by-Shlomo-Vaknin.pdf
    • http://loaminoo.linkpc.net/4095096092090/The-New-Answers-Book-1-Over-25-Questions-on-Creation-Evolution-and-the-Bible-by-Ken-Ham.pdf
    • http://loaminoo.linkpc.net/8091090093095/The-New-Answers-Book-4-Over-30-Questions-on-Evolution-Creation-and-the-Bible-by-Ken-Ham.pdf
    • http://loaminoo.linkpc.net/4095093097094099/What-Do-You-think-of-Me-Why-Do-I-Care-Answers-to-the-Big-Questions-of-Life-by-Edward-T-Welch.pdf
    • http://loaminoo.linkpc.net/9099095092096095/Asthma-Questions-You-Have-Answers-You-Need-by-Paula-Brisco-Dr-Robert-Youngson.pdf
    • http://loaminoo.linkpc.net/1091094099097096099/Multiple-Sclerosis-5th-Edition-The-Questions-You-Have-The-Answers-You-Need-by-Rosalind-C-Kalb.pdf
    • http://loaminoo.linkpc.net/5098098090092/What-If-Serious-Scientific-Answers-to-Absurd-Hypothetical-Questions-by-Randall-Munroe.pdf
    • http://loaminoo.linkpc.net/2095099092092094/Great-Answers-To-Tough-Interview-Questions-by-Martin-Yate.pdf
    • http://loaminoo.linkpc.net/1091093090093091091/The-250-Job-Interview-Questions-You-ll-Most-Likely-Be-Asked-and-the-Answers-That-Will-Get-You-Hired-by-Peter-Veruki.pdf
    • http://loaminoo.linkpc.net/7092094099091/Heaven-Biblical-Answers-to-Common-Questions-by-Randy-Alcorn.pdf
    • http://loaminoo.linkpc.net/7095093094097/A-Modern-Prophet-Answers-Your-Key-Questions-about-Life-by-Harold-Klemp.pdf
    • http://loaminoo.linkpc.net/2099097099095098/Mystery-and-Crime-The-New-York-Public-Library-Book-of-Answers-Intriguing-an