Malicious PDF — malware analysis report

Static analysis result for SHA-256 f086f9364d51571f…

MALICIOUS

PDF

14.7 KB Created: 2019-05-02 08:25:34 +01:00 Authoring application: mPDF 5.7
MD5: c8128079955c68d5b42639a9313b1f91 SHA-1: 5e19e537bbf11eb484efe92439773d6c6d2a9bf9 SHA-256: f086f9364d51571fb192ec7fdd7929d01c921199b7060948ee7c4d9b8a61701e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified as a link farm, suggesting a malicious intent to direct users to external resources. The ML classifier strongly supports the malicious verdict. While no scripts were extracted, the PDF structure and embedded URLs indicate a likely attempt to lure users to potentially malicious content or manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097096091098092/Don-t-Let-Me-Fall-by-Lakeshia-Poole.pdf
    • http://loaminoo.linkpc.net/3097095094092094/-Before-the-Fall-8-Shingeki-no-Kyojin-Before-the-Fall-8-Attack-on-Titan-Before-the-Fall-Manga-8-by-Hajime-Isayama.pdf
    • http://loaminoo.linkpc.net/8098091090097099/Somebody-Else-s-Man-by-Daaimah-S-Poole.pdf
    • http://loaminoo.linkpc.net/9093092097093/Just-Like-That-How-to-Get-Anything-You-Want-by-Janet-Poole.pdf
    • http://loaminoo.linkpc.net/4092098097092093/Br-n-by-Jeremy-Poole.pdf
    • http://loaminoo.linkpc.net/8096091096094094/Eben-by-William-T-Poole-Jr-.pdf
    • http://loaminoo.linkpc.net/4091096093090094/Joan-of-Arc-by-Josephine-Poole.pdf
    • http://loaminoo.linkpc.net/1091099090096092097/Thursday-s-Child-by-Victoria-Poole.pdf
    • http://loaminoo.linkpc.net/4097099092093090/Snow-White-by-Josephine-Poole.pdf
    • http://loaminoo.linkpc.net/2097098096094096/Insurrection-Bakkian-Chronicles-2-by-Jeffrey-M-Poole.pdf
    • http://loaminoo.linkpc.net/2091092090098090/In-Safe-Hands-Grace-amp-Poole-1-by-Lee-Christine.pdf
    • http://loaminoo.linkpc.net/1091094097091091/Bloodline-Guardian-of-the-Gate-by-Darren-Poole.pdf
    • http://loaminoo.linkpc.net/5099090096096091/Juliette-Ascending-by-Rosemary-Poole-Carter.pdf
    • http://loaminoo.linkpc.net/5090094096091/Night-Fall-What-Rises-must-Fall-Wolf-Sirens-3-by-Tina-Smith.pdf
    • http://loaminoo.linkpc.net/1091092098094098090/Graveyard-Shift-Maxi-Poole-3-by-Kelly-Lange.pdf
    • http://loaminoo.linkpc.net/8094092093091099/The-Witchcraft-Delusion-of-1692-by-William-Frederick-Poole.pdf
    • http://loaminoo.linkpc.net/1091092098094091097/Dead-File-Maxi-Poole-2-by-Kelly-Lange.pdf
    • http://loaminoo.linkpc.net/8096097099095/The-Borgia-Betrayal-The-Poisoner-Mysteries-2-by-Sara-Poole.pdf
    • http://loaminoo.linkpc.net/2092094098090090/Secret-Lives-Darke-Academy-1-by-Gabriella-Poole.pdf
    • http://loaminoo.linkpc.net/4097096095094095/Cruising-Attitude-My-Life-at-35-000-Feet-by-Heather-Poole.pdf