Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef3de9c9b8c81d7b…

MALICIOUS

PDF

15.1 KB Created: 2019-05-01 19:34:09 +01:00 Authoring application: mPDF 5.7
MD5: 2c60d6c3c76a63c9ce342f4bae31e510 SHA-1: a4ab70350f2898f99db7163fc45d18f6745112f3 SHA-256: ef3de9c9b8c81d7b21c83d8d0a6d0d0656b49995626091fce111be4ed9b8e4d8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files hosted on loaminoo.linkpc.net. While the individual URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096094098090090/Hey-Canada-by-Vivien-Bowers.pdf
    • http://loaminoo.linkpc.net/8099091093096095/Gun-Law-of-Phoenix-Cline-by-Terrell-L-Bowers.pdf
    • http://loaminoo.linkpc.net/9098091099094097/Taming-Mr-Flirt-by-A-M-Madden.pdf
    • http://loaminoo.linkpc.net/9098091099094092/The-Flirt-by-Marion-Chesney.pdf
    • http://loaminoo.linkpc.net/9098091099092093/Flirt-by-Tracy-Brown.pdf
    • http://loaminoo.linkpc.net/3096096094094092/Flirt-by-Lucia-Jordan.pdf
    • http://loaminoo.linkpc.net/2098092097092/Living-Together-New-And-Selected-Poems-by-Edgar-Bowers.pdf
    • http://loaminoo.linkpc.net/6091096098090096/How-to-Flirt-With-Girls-by-Neau-Baudi.pdf
    • http://loaminoo.linkpc.net/3099093095099094/Flirt-Club-by-Cathleen-Daly.pdf
    • http://loaminoo.linkpc.net/1093090095090099/The-Rook-The-Patrick-Bowers-Files-2-by-Steven-James.pdf
    • http://loaminoo.linkpc.net/1093091096095094/The-Queen-Patrick-Bowers-Files-5-by-Steven-James.pdf
    • http://loaminoo.linkpc.net/4093098092098093/My-Mission-to-Spain-Watching-the-Rehearsal-for-World-War-II-by-Claude-G-Bowers.pdf
    • http://loaminoo.linkpc.net/4098099098090093/Never-Flirt-with-Puppy-Killers-And-Other-Better-Book-Titles-by-Dan-Wilbur.pdf
    • http://loaminoo.linkpc.net/5094093099091094/The-Great-Gatsby-By-F-Scott-Fitzgerald-Literature-Guide-by-Kristen-Bowers.pdf
    • http://loaminoo.linkpc.net/4090099094097095/Every-Crooked-Path-The-Bowers-Files-The-New-York-Years-1-by-Steven-James.pdf
    • http://loaminoo.linkpc.net/1099099096098091/Flirt-Anita-Blake-Vampire-Hunter-18-by-Laurell-K-Hamilton.pdf
    • http://loaminoo.linkpc.net/3097097098091099/Taming-the-Enforcer-s-Flirt-A-Paranormal-s-Love-4-by-Charlie-Richards.pdf
    • http://loaminoo.linkpc.net/6098094096095093/Laura-s-Album-A-Remembrance-Scrapbook-of-Laura-Ingalls-Wilder-by-William-Anderson.pdf
    • http://loaminoo.linkpc.net/2093093096094090/Laura-s-Early-Years-Collection-Little-House-1-2-4-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/2090094099097095/Beautiful-Angiola-The-Lost-Sicilian-Folk-and-Fairy-Tales-of-Laura-Gonzenbach-by-Laura-Gonzenbach.pdf
    • http://loaminoo.linkpc.net/5094093099091094/The-Great-Gatsby-By-F-Scott-Fitzgerald-Liter