Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0de141b2e55cab0…

MALICIOUS

PDF

17.9 KB Created: 2019-04-30 03:17:51 +01:00 Authoring application: mPDF 5.7
MD5: b0101175496cba87b6f7c635d1dc8f17 SHA-1: d28bade7cdad6e09b6c5b5e549848492563cd0f7 SHA-256: e0de141b2e55cab00004e934ad43536feebd38ece7f0178480cde19e4d3d7e67
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by ClamAV as Pdf.Dropper.Agent-7076467-0 and a machine learning classifier. Static analysis revealed a large number of embedded links to external PDF files hosted on loaminoo.linkpc.net. While these specific URLs were labeled as confirmed benign, the sheer volume and the heuristic firing of PDF_SEO_LINK_FARM indicate a likely attempt to manipulate search results or redirect users to potentially malicious content, classifying it as a dropper.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7076467-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7076467-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099093099099090/Sebastian-and-the-Afterlife-by-William-J-Barry.pdf
    • http://loaminoo.linkpc.net/1096096091098099/The-Temporary-Gentleman-by-Sebastian-Barry.pdf
    • http://loaminoo.linkpc.net/3095098096094/The-Secret-Scripture-by-Sebastian-Barry.pdf
    • http://loaminoo.linkpc.net/4099098098095093/Actual-Innocence-Five-Days-to-Execution-and-Other-Dispatches-From-the-Wrongly-Convicted-by-Barry-Scheck.pdf
    • http://loaminoo.linkpc.net/2092095099099098/A-Long-Long-Way-by-Sebastian-Barry.pdf
    • http://loaminoo.linkpc.net/3094099091091090/Live-Right-and-Find-Happiness-Although-Beer-is-Much-Faster-Life-Lessons-and-Other-Ravings-from-Dave-Barry-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/1090094098096/I-ll-Mature-When-I-m-Dead-Dave-Barry-s-Amazing-Tales-of-Adulthood-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/3098095097098097/Dave-Barry-s-Money-Secrets-Like-Why-Is-There-a-Giant-Eyeball-on-the-Dollar-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/3096091095098092/Barry-Trotter-and-the-Shameless-Parody-Barry-Trotter-1-by-Michael-Gerber.pdf
    • http://loaminoo.linkpc.net/1090091094092093095/Barry-Maitland-Books-2017-Checklist-Reading-Order-of-Brock-and-Kolla-Mysteries-The-Belltree-Trilogy-and-List-of-All-Barry-Maitland-Books-by-Sorted-Guide.pdf
    • http://loaminoo.linkpc.net/6095095091093/Dave-Barry-s-Complete-Guide-to-Guys-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/4095092093090095/Eleven-Days-An-Unexpected-Love-Days-Trilogy-1-by-Lora-Lindy.pdf
    • http://loaminoo.linkpc.net/1092092094094/Lakota-Legacy-Wolf-Dreamer-Cowboy-Days-And-Indian-Nights-Seven-Days-by-Madeline-Baker.pdf
    • http://loaminoo.linkpc.net/4096097091/Christmas-Days-12-Stories-and-12-Feasts-for-12-Days-by-Jeanette-Winterson.pdf
    • http://loaminoo.linkpc.net/2099093090096097/Dave-Barry-Turns-Forty-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/2098095096093097/Dave-Barry-s-Only-Travel-Guide-You-ll-Ever-Need-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/2099095093093093/Dave-Barry-Hits-Below-the-Beltway-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/3099091097090090/More-of-Dave-Barry-s-Greatest-Hits-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/3094099090090093/30-Days-of-Night-Vol-2-Dark-Days-by-Steve-Niles.pdf
    • http://loaminoo.linkpc.net/2096096091099099/How-to-Seduce-an-Angel-in-10-Days-10-Days-3-by-Saranna-DeWylde.pdf
    • http://loaminoo.linkpc.net/1090094098096/I-ll-Mature-When-I-m-Dead-Dave