Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9b2126eb38f0ca6…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 04:27:10 +01:00 Authoring application: mPDF 5.7
MD5: b7586ec0e0f26dd50c9e3d61dee89f38 SHA-1: 76aee20d9fc3c04e67f92282d8cfacbd31146c05 SHA-256: e9b2126eb38f0ca6e24c92ee96271189bee373fd602d9aece6936dafc034c2a2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a critical heuristic for containing a mass external link farm, with 23 links identified. The ML classifier also strongly indicated maliciousness. While no scripts were extracted, the PDF structure itself is designed to lure users to a domain hosting numerous book-related links, likely as a SEO spam or phishing precursor.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7093091091091092/The-Honorable-Schoolboy-by-John-le-Carr-.pdf
    • http://loaminoo.linkpc.net/4098099095090/John-Le-Carr-Three-Complete-Novels-Tinker-Tailor-Soldier-Spy-The-Honourable-Schoolboy-Smiley-s-People-by-John-le-Carr-.pdf
    • http://loaminoo.linkpc.net/1092099092092097/The-Honourable-Schoolboy-by-John-le-Carre-Summary-Study-Guide-by-BookRags.pdf
    • http://loaminoo.linkpc.net/7093091090098094/An-Honorable-Profession-A-Novel-by-John-L-39-Heureux.pdf
    • http://loaminoo.linkpc.net/6099094096096090/The-John-Dickson-Carr-Treasury-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/5092096092099/The-Honorable-Knight-The-Fellowship-of-the-Ancient-Covenant-Book-1-by-Patrick-John-Donahoe.pdf
    • http://loaminoo.linkpc.net/6092092093097094/The-Identity-of-the-Christ-Understanding-the-Fulfillment-of-the-Christ-Through-Master-Fard-Muhammad-the-Honorable-Elijah-Muhammad-and-the-Honorable-Louis-Farrakhan-by-Karriem-Allah.pdf
    • http://loaminoo.linkpc.net/5092091097091095/John-Owen-by-Simonetta-Carr.pdf
    • http://loaminoo.linkpc.net/2096097094092096/Hag-s-Nook-Dr-Gideon-Fell-1-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/1091092095091098096/Der-Teufel-in-Samt-Roman-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/3094094095098090/Life-in-France-under-Louis-XIV-by-John-Laurence-Carr.pdf
    • http://loaminoo.linkpc.net/2093097090097095/The-Three-Coffins-Dr-Gideon-Fell-6-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/3095096096095097/The-Crooked-Hinge-Dr-Gideon-Fell-8-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/3096091092090097/The-Corpse-in-the-Waxworks-Henri-Bencolin-4-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/2093097093097091/The-Life-of-Sir-Arthur-Conan-Doyle-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/3095096097098094/The-Problem-of-the-Green-Capsule-Dr-Gideon-Fell-10-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/4099092092098093/Till-Death-Do-Us-Part-Dr-Gideon-Fell-15-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/2092097098090094/The-Case-of-the-Constant-Suicides-Dr-Gideon-Fell-13-by-John-Dickson-Carr.pdf
    • http://loaminoo.linkpc.net/1093098098090097/Schoolboy-Into-War-by-H-E-L-Mellersh.pdf
    • http://loaminoo.linkpc.net/1098092094097092/The-Schoolboy-s-Story-by-Charles-Dickens.pdf
    • http://loaminoo.linkpc.net/6092092093097094/The-Identity-of-the-Christ-Understanding-the-Fulfillment-of-the-Christ-Through-Master-Fard-Muhammad-the-Honorable-Elijah-Muh