Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3161703d818ffa7…

MALICIOUS

PDF

21.2 KB Created: 2019-04-30 19:00:23 +01:00 Authoring application: mPDF 5.7
MD5: 1203c54e69f0c90d3724ca10dd78dec7 SHA-1: ee1afdfac7b2719b16137962c54f4285ba537e4a SHA-256: f3161703d818ffa70a191393e9fbb6dfae4e1657777da96a29dc7bba5290c282
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm with 25 external links, primarily pointing to book-related PDFs hosted on loaminoo.linkpc.net. This heuristic, combined with the ML classifier's high confidence, indicates a malicious intent to distribute further content. No scripts were extracted from this sample, but the structure suggests a lure to download potentially malicious files disguised as legitimate documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090097099097091/Skulduggery-Pleasant-1-5-Skulduggery-Pleasant-1-5-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1090094095098098090/Skulduggery-Pleasant-1-3-Skulduggery-Pleasant-1-3-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/4093090091097/Skulduggery-Pleasant-Skulduggery-Pleasant-1-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1090094095098097099/Skulduggery-Pleasant-4-6-Skulduggery-Pleasant-4-6-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1090094095098099095/Skulduggery-Pleasant-1-7-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/3095094095097093/Midnight-Skulduggery-Pleasant-11-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1091091099092090094/Skulduggery-Pleasant---Apokalypse-Wow-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/6090091092094/The-Faceless-Ones-Skulduggery-Pleasant-3-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1090094096090091099/Skulduggery-Pleasant-Reihe-in-7-B-nden-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/4094098093090/The-Dying-of-the-Light-Skulduggery-Pleasant-9-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/2096095090095095/Kingdom-of-the-Wicked-Skulduggery-Pleasant-7-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/2094090094094097/Playing-with-Fire-Skulduggery-Pleasant-2-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/4095092090093/Armageddon-Outta-Here-Skulduggery-Pleasant-8-5-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/6090097090098/Death-Bringer-Skulduggery-Pleasant-6-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/3094099092092/Mortal-Coil-Skulduggery-Pleasant-5-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/6097098099090/The-Lost-Art-of-World-Domination-Skulduggery-Pleasant-1-5-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1090094095098098091/Articles-on-Skulduggery-Pleasant-Books-Including-Skulduggery-Pleasant-List-of-Skulduggery-Pleasant-Characters-Skulduggery-Pleasant-Playing-with-Fire-Skulduggery-Pleasant-The-Faceless-Ones-Skulduggery-Pleasant-Series-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/1090094095098098096/The-Slightly-Ignominious-End-to-the-Legend-of-Black-Annis-Skulduggery-Pleasant-3-5-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/1090094096090097098/Skulduggery-Pleasant---Males-Amity-Anathem-Mire-Anton-Shudder-Argus-Auron-Tenebrae-Baron-Vengeous-Batu-Billy-Ray-Sanguine-Bison-Dragonclaw-Burgundy-Dalrymple-Caelan-Cameron-Light-Civet-Corrival-Deuce-Desmond-Edgley-Dexter-Vex-Dreylan-S-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/4096091094095098/Demon-Road-Demon-Road-1-by-Derek-Landy.pdf
    • http://loaminoo.linkpc.net/4095092090093/Armageddon-Outta-Here-Skulduggery-Pleasant-8-5-by-Derek-Landy