Malicious PDF — malware analysis report

Static analysis result for SHA-256 f0d7ddcf42eef291…

MALICIOUS

PDF

25.1 KB Created: 2019-04-29 23:24:20 +01:00 Authoring application: mPDF 5.7
MD5: ca6be0ea66dc5e18037e7b84618c1fdc SHA-1: 15edd19f46ba86a50e16ccf91af575a09d3d15bb SHA-256: f0d7ddcf42eef29114ff84f51e17ced0b208fca8064ab26d94245ca8ac45f8df
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier strongly suggests maliciousness. While no scripts were extracted, the sheer volume of links points to a likely SEO poisoning or redirection attack. The URLs themselves appear to be benign, but their purpose in this context is suspicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9906

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8095098091095096/Persuasion-Special-Annotated-Edition-The-World-of-Jane-Austen-6-The-World-of-Jane-Austen-Series-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1091097097091090093/Four-Major-Works-by-Jane-Austen-Northanger-Abbey-Lady-Susan-Sense-and-Sensibility-Pride-and-Prejudice-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1091097097090097096/Jane-Austen-Four-Novels-Sense-and-Sensibility-Pride-and-Prejudice-Emma-Northanger-Abbey-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1091097096099092097/The-Illustrated-Works-Of-Jane-Austen-Sense-and-Sensibility-Emma-Northanger-Abbey-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/8097090092095/The-Complete-Novels-of-Jane-Austen-Volume-II-Emma-Northanger-Abbey-Persuasion-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/2098092091094095/All-Roads-Lead-to-Austen-A-Yearlong-Journey-with-Jane-by-Amy-Elizabeth-Smith.pdf
    • http://loaminoo.linkpc.net/5097092090099092/MANSFIELD-PARK---JANE-AUSTEN-WITH-NOTES-BIOGRAPHY-ILLUSTRATED-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/9091095097090/Jane-Austen-Pride-and-Prejudice-Mansfield-Park-Persuasion-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/5095098094096095/The-Novels-of-Jane-Austen-Northanger-Abbey-In-Ten-Volumes-Vol-IX-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/5093091098097094/NORTHANGER-ABBEY-by-Jane-Austen-author-of-Sense-and-Sensibility-Pride-and-Prejudice-Persuasion-Emma-Mansfield-Park-Nothanger-Abbey-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/6090095091095093/L-Abbaye-de-Northanger---Le-seul-roman-gothique-de-Jane-Austen-L-dition-int-grale-Northanger-Abbey-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/1096095092093090/Rude-Awakenings-of-a-Jane-Austen-Addict-Jane-Austen-Addict-2-by-Laurie-Viera-Rigler.pdf
    • http://loaminoo.linkpc.net/6097093092096091/PRIDE-AND-PREJUDICE-Jane-Austen-author-of-Mansfield-Park-Persuasion-Sense-and-Sensibility-Northanger-Pride-and-Prejudice-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/6092096092099099/SENSE-AND-SENSIBILITY-by-Jane-Austen-author-of-Mansfield-Park-Persuasion-Sense-and-Sensibility-Northanger-Pride-and-Prejudice-Annotated-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/8096094099093/Confessions-of-a-Jane-Austen-Addict-Jane-Austen-Addict-1-by-Laurie-Viera-Rigler.pdf
    • http://loaminoo.linkpc.net/4098093091090090/Jane-Austen-Complete-and-Unabridged-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/2097097094090091/The-Complete-Novels-of-Jane-Austen-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/2090091099090096/Complete-Novels-Of-Jane-Austen-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/5094093092095096/The-Novels-of-Jane-Austen-Volume-7-by-Jane-Austen.pdf
    • http://loaminoo.linkpc.net/4099091098097/The-Man-Who-Loved-Jane-Austen-The-Man-Who-Loved-Jane-Austen-1-by-Sally-Smith-O-39-Rourke.pdf
    • http://loaminoo.linkpc.net/809709009209