Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9e3cf54409986fc…

MALICIOUS

PDF

16.4 KB Created: 2019-04-29 23:15:37 +01:00 Authoring application: mPDF 5.7
MD5: b5bbea0cf54aed3cad0e014baf86889c SHA-1: 63e238cfceb067e307c9b0bb8d8802e6d4658c5d SHA-256: e9e3cf54409986fccddc5551af9199c3d8fa290f69a1c29bdb1a0dc8b8fa48ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged as malicious by an ML classifier. It contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files hosted on loaminoo.linkpc.net. The purpose appears to be SEO manipulation or distributing further malicious content through these links. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095093096093/More-Than-a-Man-43-Light-Street-32-by-Rebecca-York.pdf
    • http://loaminoo.linkpc.net/2090099092095/Never-Alone-43-Light-Street-22-by-Rebecca-York.pdf
    • http://loaminoo.linkpc.net/1092096093093/For-Your-Eyes-Only-43-Light-Street-14-by-Rebecca-York.pdf
    • http://loaminoo.linkpc.net/4093094095092097/Bad-Nights-Rockfort-Security-1-by-Rebecca-York.pdf
    • http://loaminoo.linkpc.net/4096092094098092/Decorah-Security-Collection-by-Rebecca-York.pdf
    • http://loaminoo.linkpc.net/4098092099095097/On-Edge-Decorah-Security-0-5-by-Rebecca-York.pdf
    • http://loaminoo.linkpc.net/1098093094098/Misplaced-New-York-City-s-Street-Kids-by-Alexia-J-Lewnes.pdf
    • http://loaminoo.linkpc.net/1090095098096095091/75-Pretzels-A-New-York-Tale-Memoirs-of-a-Street-Peddler-by-Michael-Marzi.pdf
    • http://loaminoo.linkpc.net/1091099098095092092/Light-Up-New-York-by-Natalie-Grant.pdf
    • http://loaminoo.linkpc.net/5091096099097097/The-Light-Within-by-Rebecca-L-Matthews.pdf
    • http://loaminoo.linkpc.net/3090096091098092/First-Light-by-Rebecca-Stead.pdf
    • http://loaminoo.linkpc.net/3095097098095097/A-Light-Amongst-Shadows-Dark-is-the-Night-1-by-Kelley-York.pdf
    • http://loaminoo.linkpc.net/2092098092093092/Dragon-Moon-Moon-9-by-Rebecca-York.pdf
    • http://loaminoo.linkpc.net/8098099092090099/Voices-From-The-Street-An-Ethnography-Of-India-s-Street-Children-A-Case-Study-Of-Delhi-by-Lori-McFadyen.pdf
    • http://loaminoo.linkpc.net/8097091094091/Echoes-of-Scotland-Street-On-Dublin-Street-5-by-Samantha-Young.pdf
    • http://loaminoo.linkpc.net/2099093093095091/Echoes-of-Scotland-Street-On-Dublin-Street-5-by-Samantha-Young.pdf
    • http://loaminoo.linkpc.net/8096091095094097/New-York-New-York-Elysian-Park-Zwei-St-cke-by-Marlene-Streeruwitz.pdf
    • http://loaminoo.linkpc.net/8095099095091097/Portraits-de-New-York-New-York-par-ceux-qui-y-vivent-by-Jeanne-Sulzer.pdf
    • http://loaminoo.linkpc.net/1091093099091095092/The-Potential-of-Cross-Marketing-for-the-Destination-Management-Organizations-of-New-York-City-and-New-York-State-by-Yvonne-Koppen.pdf
    • http://loaminoo.linkpc.net/3090090094098092/Quickies-in-New-York-Stories-Winter-To-Spring-by-Guy-New-York.pdf