Malicious PDF — malware analysis report

Static analysis result for SHA-256 f03da8ac3abadc87…

MALICIOUS

PDF

15.9 KB Created: 2019-05-02 05:10:53 +01:00 Authoring application: mPDF 5.7
MD5: 1eb1ba7ff2aa2c400aaca2c17f8e554d SHA-1: 8e807cfffdb726a38a3b7cb555dc0d19a4f4eeaa SHA-256: f03da8ac3abadc8760077ebe0e946945baa403ed9271b443223f2688ecc385d9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' and the sheer volume of links suggest a malicious intent to redirect users or manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097094090092099/Sea-and-Sardinia-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/8094091098093090/Sons-and-Lovers-1913-Novel-by-D-H-Lawrence-100-Best-Novels-of-the-20th-Century-Include-Women-in-Love-1920-Novel-By-D-H-Lawrence-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/4093092094095093/The-Golden-Warrior-The-Life-and-Legend-of-Lawrence-of-Arabia-by-Lawrence-James.pdf
    • http://loaminoo.linkpc.net/1090093099090092098/THE-PLUMED-SERPENT-by-D-H-Lawrence-author-of-Sons-and-Lovers-The-Rainbow-Women-in-Love-and-Lady-Chatterley-s-Lover-Annotated-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/3091092096092097/D-H-Lawrence-and-Italy-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/1091092091096092097/The-Works-of-D-H-Lawrence-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/1090096097097092097/Lawrence-Welk-s-Polka-Folio-Piano-amp-Piano-Accordion-by-Lawrence-Welk.pdf
    • http://loaminoo.linkpc.net/1090096097095095097/Wunnerful-Wunnerful-The-Autobiography-of-Lawrence-Welk-by-Lawrence-Welk.pdf
    • http://loaminoo.linkpc.net/3092097096092098/Already-Gone-by-Jeremy-Lawrence.pdf
    • http://loaminoo.linkpc.net/4090090099091096/Anatomic-by-Ali-Lawrence.pdf
    • http://loaminoo.linkpc.net/4095097094093091/The-Boy-in-the-Bush-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/5091092094099090/Always-the-Love-of-Someone-by-Huw-Lawrence.pdf
    • http://loaminoo.linkpc.net/2093091096099093/The-Rainbow-by-D-H-Lawrence.pdf
    • http://loaminoo.linkpc.net/1095090099099/What-We-Don-t-Know-About-Each-Other-by-Lawrence-Raab.pdf
    • http://loaminoo.linkpc.net/1090099099096096097/In-s-er-Ruh-by-C-E-Lawrence.pdf
    • http://loaminoo.linkpc.net/1090094093096093093/A-Cup-of-Quarrels-by-A-Rhoden-Lawrence.pdf
    • http://loaminoo.linkpc.net/2092098090094096/Mountolive-by-Lawrence-Durrell.pdf
    • http://loaminoo.linkpc.net/1091095099096096/Woodline-by-Lawrence-Crossett.pdf
    • http://loaminoo.linkpc.net/1091091093093094/Ghost-Boy-by-Iain-Lawrence.pdf
    • http://loaminoo.linkpc.net/3097092090096099/Out-of-darkness-by-Lawrence-W-Gold.pdf