Malicious PDF — malware analysis report

Static analysis result for SHA-256 f05459adb0a198bf…

MALICIOUS

PDF

13.4 KB Created: 2019-05-01 23:56:33 +01:00 Authoring application: mPDF 5.7
MD5: ca1b2b0f83ac6acdb3abdc6b1cb1066f SHA-1: 5650187177371b0a843c9883945206c26898bfbf SHA-256: f05459adb0a198bf98fc9ab44aae8a53e66688097579232f88654d1e21307d55
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely to redirect users to malicious content or for SEO spam. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3096095090096094/Sea-of-Slaughter-by-Farley-Mowat.pdf
    • http://loaminoo.linkpc.net/8095094092099/Owls-in-the-Family-by-Farley-Mowat.pdf
    • http://loaminoo.linkpc.net/1092095098090094/The-Serpent-s-Coil-by-Farley-Mowat.pdf
    • http://loaminoo.linkpc.net/8094099096099090/The-Alban-Quest-by-Farley-Mowat.pdf
    • http://loaminoo.linkpc.net/1091091095096090/People-of-the-Deer-by-Farley-Mowat.pdf
    • http://loaminoo.linkpc.net/2093093094097095/A-Whale-for-the-Killing-by-Farley-Mowat.pdf
    • http://loaminoo.linkpc.net/1092091091098091/The-Grey-Seas-Under-The-Perilous-Rescue-Mission-of-a-N-A-Salvage-Tug-by-Farley-Mowat.pdf
    • http://loaminoo.linkpc.net/4092097095096099/New-Scotia-Pack-Box-Set-Shield-Wolf-Wolf-Lover-Fire-Wolf-by-Victoria-Danann.pdf
    • http://loaminoo.linkpc.net/5099095091094095/Dracula-by-Diane-Mowat.pdf
    • http://loaminoo.linkpc.net/1098091094/Wolf-by-Wolf-Wolf-by-Wolf-1-by-Ryan-Graudin.pdf
    • http://loaminoo.linkpc.net/8090095092097/The-Monkey-s-Paw-Oxford-Bookworms-by-Diane-Mowat.pdf
    • http://loaminoo.linkpc.net/1091098094092098095/A-Morbid-Taste-for-Bones-by-Diane-Mowat.pdf
    • http://loaminoo.linkpc.net/9097097097093098/Death-of-an-Englishman-Oxford-Bookworms-Stage-4-by-Diane-Mowat.pdf
    • http://loaminoo.linkpc.net/4099097099091092/Man-O-War-by-Walter-Farley.pdf
    • http://loaminoo.linkpc.net/1090096090098092/Man-O-War-by-Walter-Farley.pdf
    • http://loaminoo.linkpc.net/6092096094090096/Wolf-Erlbruchs-Kinderzimmer-Kalender-2015-Geschwister-by-Wolf-Erlbruch.pdf
    • http://loaminoo.linkpc.net/1092093095097097/My-Wolf-Protector-Wolf-Town-Guardians-2-by-Rose-Wynters.pdf
    • http://loaminoo.linkpc.net/1091093099098090090/Her-Wolf-Her-Protector-Claimed-and-Bred-by-the-Wolf-1-by-Elixa-Everett.pdf
    • http://loaminoo.linkpc.net/1091095092091099/The-Big-Bad-Wolf-Romance-Compilation-The-Big-Bad-Wolf-1-4-by-Heather-Killough-Walden.pdf
    • http://loaminoo.linkpc.net/4098091092096096/SEAL-Wolf-In-Too-Deep-Heart-of-the-Wolf-18-by-Terry-Spear.pdf