Malicious PDF — malware analysis report

Static analysis result for SHA-256 f06a649ab635282c…

MALICIOUS

PDF

15.8 KB Created: 2019-05-01 18:51:15 +01:00 Authoring application: mPDF 5.7
MD5: b5136e3158eaa117800fdd87f0d200ef SHA-1: 64f2e07b6ced3ad50cb51bb7e337ed2f3faf4361 SHA-256: f06a649ab635282c689b52d22ba7ef17306417b6c36c938696c04ac496b03c8c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs extracted are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to redirect users to malicious sites. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3094091092091092/Rock-the-Dream-A-Stand-Alone-Novel-in-the-Redfall-Dream-Series-Book-1-by-B-B-Miller.pdf
    • http://loaminoo.linkpc.net/4091090098095098/Dream-a-Little-Christmas-Dream-Dream-a-Little-Dream-1-5-by-Giovanna-Fletcher.pdf
    • http://loaminoo.linkpc.net/1090095095099097095/Lighthouse-Dreams-The-Dream-Series-Book-1-by-Marica-Vance.pdf
    • http://loaminoo.linkpc.net/1090095096090095097/Dreaming-You-ll-Find-Me-The-Dream-Series-Book-3-by-Marica-Vance.pdf
    • http://loaminoo.linkpc.net/4093091095093096/Wet-Dream-1Night-Stand-24-by-J-M-Madden.pdf
    • http://loaminoo.linkpc.net/1099091091094093/Prochownik-s-Dream-by-Alex-Miller.pdf
    • http://loaminoo.linkpc.net/1096094098097095/Rock-Star-Dream-Weaver-2-by-Su-Williams.pdf
    • http://loaminoo.linkpc.net/4098090096091098/Good-Dream-Bad-Dream-The-World-s-Heroes-Save-the-Night-by-Juan-Calle.pdf
    • http://loaminoo.linkpc.net/3097098094093091/A-Dictionary-of-Dream-Symbols-With-an-Introduction-to-Dream-Psychology-by-Eric-Ackroyd.pdf
    • http://loaminoo.linkpc.net/3098099096092094/A-Wish-a-Kiss-a-Dream-Cowboys-and-Captives-2-Dream-4-by-Shiloh-Walker.pdf
    • http://loaminoo.linkpc.net/1092097091098/Daring-to-Dream-Dream-Trilogy-1-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/4099095097092099/Another-Dream-Another-Reality-Another-Dream-2-by-Mechele-Armstrong.pdf
    • http://loaminoo.linkpc.net/4099095097093096/Another-Night-Another-Dream-Another-Dream-1-by-Mechele-Armstrong.pdf
    • http://loaminoo.linkpc.net/2090098094093093/Dream-Team-Dream-Seekers-2-by-Lisa-Ard.pdf
    • http://loaminoo.linkpc.net/2099098096091092/Ditching-the-Dream-Dream-1-by-Isabelle-Peterson.pdf
    • http://loaminoo.linkpc.net/3090092099090093/Chasing-the-Dream-Dream-3-by-Isabelle-Peterson.pdf
    • http://loaminoo.linkpc.net/9093096/Leave-Your-Mark-Land-Your-Dream-Job-Kill-It-in-Your-Career-Rock-Social-Media-by-Aliza-Licht.pdf
    • http://loaminoo.linkpc.net/2096094094094095/Dream-Student-Dream-1-by-J-J-DiBenedetto.pdf
    • http://loaminoo.linkpc.net/5095096099095095/Dream-a-Little-Dream-by-Kerstin-Gier.pdf
    • http://loaminoo.linkpc.net/1096098093095093/Dream-Reunion-Dream-6-by-J-J-DiBenedetto.pdf
    • http://loaminoo.linkpc.net/1092097091098/Daring-to-Dream-Dream-Trilogy-1-by-Nora-Roberts.pd