Malicious PDF — malware analysis report

Static analysis result for SHA-256 e696f8a706929c74…

MALICIOUS

PDF

21.9 KB Created: 2019-05-03 05:43:30 +01:00 Authoring application: mPDF 5.7
MD5: c50b781e387fa91056ed9da0bbfe52d3 SHA-1: 061465b858aa270a0c580904b43738442518a58a SHA-256: e696f8a706929c74f1cdc0cd2d59629b413750d4a91ffb9d94a63ed518f7de61
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves appear to link to books and are marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO spam or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9919

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5093091090091/A-Fountain-Filled-with-Blood-Rev-Clare-Fergusson-amp-Russ-Van-Alstyne-Mysteries-2-by-Julia-Spencer-Fleming.pdf
    • http://loaminoo.linkpc.net/3091094099093/I-Shall-Not-Want-Rev-Clare-Fergusson-amp-Russ-Van-Alstyne-Mysteries-6-by-Julia-Spencer-Fleming.pdf
    • http://loaminoo.linkpc.net/1096099097096/Out-of-the-Deep-I-Cry-Rev-Clare-Fergusson-amp-Russ-Van-Alstyne-Mysteries-3-by-Julia-Spencer-Fleming.pdf
    • http://loaminoo.linkpc.net/2091097094096094/Letters-to-a-Soldier-Rev-Clare-Fergusson-amp-Russ-Van-Alstyne-Mysteries-6-5-by-Julia-Spencer-Fleming.pdf
    • http://loaminoo.linkpc.net/2096098096097/In-the-Bleak-Midwinter-The-Rev-Clare-Fergusson-amp-Russ-Van-Alstyne-Mysteries-1-by-Julia-Spencer-Fleming.pdf
    • http://loaminoo.linkpc.net/2096099094093/Through-the-Evil-Days-Rev-Clare-Fergusson-amp-Russ-Van-Alstyne-Mysteries-8-by-Julia-Spencer-Fleming.pdf
    • http://loaminoo.linkpc.net/3092093093096098/Through-the-Evil-Days-Rev-Clare-Fergusson-amp-Russ-Van-Alstyne-Mysteries-8-by-Julia-Spencer-Fleming.pdf
    • http://loaminoo.linkpc.net/1093096092096098/The-Haunted-Fountain-Judy-Bolton-Mysteries-28-by-Margaret-Sutton.pdf
    • http://loaminoo.linkpc.net/9098099096096096/Heimliche-Liebe-Julia-1582-by-Catherine-Spencer.pdf
    • http://loaminoo.linkpc.net/6091099091091097/Back-to-St-Clare-s-Second-Form-at-St-Clare-s---Claudine-at-St-Clare-s---Fifth-Formers-of-St-Clare-s-by-Enid-Blyton.pdf
    • http://loaminoo.linkpc.net/7097096093099099/Last-Lair-of-Wolves-Inspector-Le-Fleming-Mysteries-Book-1-by-Sean-Frain.pdf
    • http://loaminoo.linkpc.net/3099091098096099/Bad-Blood-DI-Marjory-Fleming-8-by-Aline-Templeton.pdf
    • http://loaminoo.linkpc.net/7091098099097093/Ashes-of-the-Elements-Hawkenlye-Mysteries-2-by-Alys-Clare.pdf
    • http://loaminoo.linkpc.net/2092091099092097/Doc-Gutson-s-Revenge-Bella-Street-Mysteries-2-by-Clare-Havens.pdf
    • http://loaminoo.linkpc.net/2092091099093096/The-Secret-Formula-Bella-Street-Mysteries-1-by-Clare-Havens.pdf
    • http://loaminoo.linkpc.net/3095095090092093/Losing-Your-Head-The-Charlie-Davies-Mysteries-Book-1-by-Clare-Kauter.pdf
    • http://loaminoo.linkpc.net/2090096095099093/Baying-For-Blood-Indigo-Skies-2-by-Rebecca-Clare-Smith.pdf
    • http://loaminoo.linkpc.net/6091099091092097/St-Clare-s-Claudine-At-St-Clare-s-amp-Fifth-Formers-At-St-Clare-s-by-Enid-Blyton.pdf
    • http://loaminoo.linkpc.net/5098095097099098/Cme-Fleming-S-Art-And-Ideas-10e-by-William-Fleming.pdf
    • http://loaminoo.linkpc.net/3093095099099093/Blood-in-the-Fields-Ten-Years-Inside-California-s-Nuestra-Familia-Gang-by-Julia-Reynolds.pdf
    • http://loaminoo.linkpc.net/2091097094096094/Letters-to-a-Soldier-Rev-Clare-Fergusson-amp-Russ-Van-Alsty