Malicious PDF — malware analysis report

Static analysis result for SHA-256 f06df1b10db0a0bd…

MALICIOUS

PDF

29.8 KB Created: 2019-05-02 06:59:35 +01:00 Authoring application: mPDF 5.7
MD5: b3dd47510157e76027e01d3436b378a4 SHA-1: 4b8c775d014f9d0e98c7ec30e62821f1e877f4f7 SHA-256: f06df1b10db0a0bd4e99edc1855cd7ce2f74bccf204897c064118f3404112199
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection scheme. The ML classifier also flagged the document as malicious. While no scripts were extracted, the sheer volume of links points to a malicious intent, likely to drive traffic or distribute further payloads. The primary IOCs are the URLs found within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9885

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6099097097090097/Great-Bastards-of-History-True-and-Riveting-Accounts-of-the-Most-Famous-Illegitimate-Children-Who-Went-on-to-Achieve-Greatness-by-Jur-Fiorillo.pdf
    • http://loaminoo.linkpc.net/2090097098099098/Soul-Patrol-The-Riveting-True-Story-of-the-First-African-American-LRRP-Team-in-Vietnam-by-Ed-Emanuel.pdf
    • http://loaminoo.linkpc.net/1090092097096091/If-You-Survive-From-Normandy-to-the-Battle-of-the-Bulge-to-the-End-of-World-War-II-One-American-Officer-s-Riveting-True-Story-by-George-Wilson.pdf
    • http://loaminoo.linkpc.net/3096097093099092/History-Revisited-The-Great-Battles-Eminent-Historians-Take-on-the-Great-Works-of-Alternative-History-by-J-David-Markham.pdf
    • http://loaminoo.linkpc.net/2091090096099093/Oregon-Trail-Stories-True-Accounts-of-Life-in-a-Covered-Wagon-by-David-Klausmeyer.pdf
    • http://loaminoo.linkpc.net/2099094093093092/I-Am-Not-Afraid-Demon-Possession-and-Spiritual-Warfare-True-Accounts-from-the-Lutheran-Church-of-Madagascar-by-Robert-H-Bennett.pdf
    • http://loaminoo.linkpc.net/1091093095097098098/The-Winner-s-Brain-8-Strategies-Great-Minds-Use-to-Achieve-Success-by-Jeff-Brown.pdf
    • http://loaminoo.linkpc.net/9090094098098092/The-Cold-War-A-History-in-Documents-and-Eyewitness-Accounts-by-Jussi-M-Hanhim-ki.pdf
    • http://loaminoo.linkpc.net/8093093090091090/The-Demonologist-The-Extraordinary-Career-of-Ed-and-Lorraine-Warren-The-True-Accounts-of-the-Paranormal-Investigators-Featured-in-the-Blockbuster-Film-The-Conjuring-by-Gerald-Brittle.pdf
    • http://loaminoo.linkpc.net/5090097090096/The-History-of-the-Ancient-World-From-the-Earliest-Accounts-to-the-Fall-of-Rome-by-Susan-Wise-Bauer.pdf
    • http://loaminoo.linkpc.net/6093091097098093/Memories-of-the-Great-and-the-Famous-by-Hilarion-Henares.pdf
    • http://loaminoo.linkpc.net/4094091090097095/What-Happened-to-Their-Kids-Children-of-the-Rich-and-Famous-by-Malcolm-Forbes.pdf
    • http://loaminoo.linkpc.net/4094097090095098/Crazy-Good-The-True-Story-of-Dan-Patch-the-Most-Famous-Horse-in-America-by-Charles-Leerhsen.pdf
    • http://loaminoo.linkpc.net/7091095095098091/Twenty-Thousand-Leagues-Under-the-Sea----Simplified-Chinese-Edition----BookDna-Famous-Children-s-Literature-by-Jules-Verne.pdf
    • http://loaminoo.linkpc.net/3094094092098094/Secret-Lives-of-Great-Authors-What-Your-Teachers-Never-Told-You-about-Famous-Novelists-Poets-and-Playwrights-by-Robert-Schnakenberg.pdf
    • http://loaminoo.linkpc.net/9097092095094090/Major-Works-on-Religion-and-Politics-Leaves-from-the-Notebook-of-a-Tamed-Cynic-Moral-Man-and-Immoral-Society-The-Children-of-Light-and-the-Children-of-Darkness-The-Irony-of-American-History-Other-Writings-by-Reinhold-Niebuhr.pdf
    • http://loaminoo.linkpc.net/2098096099099093/Mad-Kings-amp-Queens-History-s-Most-Famous-Raving-Royals-by-Alison-Rattle.pdf
    • http://loaminoo.linkpc.net/8094091098090090/Did-God-Kill-Jesus-Searching-for-Love-in-History-s-Most-Famous-Execution-by-Tony-Jones.pdf
    • http://loaminoo.linkpc.net/5096092097/Royal-Bastards-Royal-Bastards-1-by-Andrew-Shvarts.pdf
    • http://loaminoo.linkpc.net/9092091096096099/The-President-s-House-1800-to-the-Present-The-Secrets-and-History-of-the-World-s-Most-Famous-Home-by-Margaret-Truman.pdf
    • http://loaminoo.linkpc.net/1090092097096091/If-You-Survive-From-Normandy-to-the-Battle-of-the-Bulge-to-the-End-of-World-War-II-One-American-Officer-s-Riveting-True-Story-by