Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9a06920613ba48c…

MALICIOUS

PDF

21.3 KB Created: 2019-05-02 17:07:17 +01:00 Authoring application: mPDF 5.7
MD5: fb9d9ab2b20186f26cc445ab4c98b901 SHA-1: 8620c8add2d0e2ec5cfd86d04646a1d19927d2b8 SHA-256: e9a06920613ba48c2c1aa07c27af4cf9fe6bf58fe7574debd5c2063c2e23b9fb
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, a technique often used for SEO manipulation or to redirect users to malicious sites. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the PDF structure itself suggests a delivery mechanism for potentially harmful content via these numerous links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3092094095090097/Pride-Prejudice-and-Cheese-Grits-Jane-Austen-Takes-the-South-1-by-Mary-Jane-Hathaway.pdf
    • http://loaminoo.linkpc.net/1098098091090090/Pride-Prejudice-and-Cheese-Grits-Jane-Austen-Takes-the-South-1-by-Mary-Jane-Hathaway.pdf
    • http://loaminoo.linkpc.net/1096096093090092/Pride-Prejudice-and-Cheese-Grits-Jane-Austen-Takes-the-South-1-by-Mary-Jane-Hathaway.pdf
    • http://loaminoo.linkpc.net/4092092090094097/Pride-Prejudice-and-Cheese-Grits-Jane-Austen-Takes-the-South-1-by-Mary-Jane-Hathaway.pdf
    • http://loaminoo.linkpc.net/1098098092097094/Emma-Mr-Knightley-and-Chili-Slaw-Dogs-Jane-Austen-Takes-the-South-2-by-Mary-Jane-Hathaway.pdf
    • http://loaminoo.linkpc.net/6097093092096091/PRIDE-AND-PREJUDICE-Jane-Austen-author-of-Mansfield-Park-Persuasion-Sense-and-Sensibility-Northanger-Pride-and-Prejudice-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1091097097091090093/Four-Major-Works-by-Jane-Austen-Northanger-Abbey-Lady-Susan-Sense-and-Sensibility-Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1091097097090097096/Jane-Austen-Four-Novels-Sense-and-Sensibility-Pride-and-Prejudice-Emma-Northanger-Abbey-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/9091095097090/Jane-Austen-Pride-and-Prejudice-Mansfield-Park-Persuasion-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/2098091098097096/Georgiana-Darcy-s-Diary-Jane-Austen-s-Pride-and-Prejudice-Continued-Pride-and-Prejudice-Chronicles-1-by-Anna-Elliott.pdf
    • http://loaminoo.linkpc.net/5093091098097094/NORTHANGER-ABBEY-by-Jane-Austen-author-of-Sense-and-Sensibility-Pride-and-Prejudice-Persuasion-Emma-Mansfield-Park-Nothanger-Abbey-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/6092096092099099/SENSE-AND-SENSIBILITY-by-Jane-Austen-author-of-Mansfield-Park-Persuasion-Sense-and-Sensibility-Northanger-Pride-and-Prejudice-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/5098091093090090/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/2096090091091090/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1090090097095094/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/9095094099094093/Pride-amp-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/9093090092090097/Pride-And-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/6090090099092092/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/9094096/Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/7091093092097093/Pride-and-Prejudice-by-Jane-Austen.pdf