Malicious PDF — malware analysis report

Static analysis result for SHA-256 f33ffc63274dc77e…

MALICIOUS

PDF

19.2 KB Created: 2019-04-30 02:52:24 +01:00 Authoring application: mPDF 5.7
MD5: d54ea40da33ec661c10b19af19a0794a SHA-1: 93b9afd8febf5646ea52499140f29750d1ff0133 SHA-256: f33ffc63274dc77e61aa142a0773fef844ab7afdc6336d7327b0522626d4fdae
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or distribution mechanism. The ML_NYX_PDF_MALICIOUS heuristic also flagged the file with high confidence. While no scripts were extracted, the embedded URLs are the primary indicators of malicious activity, likely serving as a lure or a method to distribute further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091097098098090091/The-Crewel-Needlepoint-World-by-Barbara-Donnelly.pdf
    • http://loaminoo.linkpc.net/1091097098098096099/The-Animal-Kingdom-Of-Erica-Wilson-21-Traceable-Crewel-amp-Amp-Needlepoint-Designs-by-Erica-Wilson.pdf
    • http://loaminoo.linkpc.net/1091097098098090093/Crewel-embroidery-made-easy-by-Barbara-McLennan.pdf
    • http://loaminoo.linkpc.net/1099098093099091/Altered-Crewel-World-2-by-Gennifer-Albin.pdf
    • http://loaminoo.linkpc.net/2096096096090099/The-Department-of-Alterations-Crewel-World-0-5-by-Gennifer-Albin.pdf
    • http://loaminoo.linkpc.net/1091097098097094095/Patterns-of-Murder-Crewel-World-Framed-in-Lace-A-Stitch-in-Time-by-Monica-Ferris.pdf
    • http://loaminoo.linkpc.net/4099094094095094/Art-Forms-in-the-Plant-World-by-Karl-Blossfeldt.pdf
    • http://loaminoo.linkpc.net/3090097099095097/Batman-amp-Superman-World-s-Finest-by-Karl-Kesel.pdf
    • http://loaminoo.linkpc.net/8098097099093093/German-Raiders-of-World-War-II-by-August-Karl-Muggenthaler.pdf
    • http://loaminoo.linkpc.net/3099097090091097/The-World-of-Parmenides-Essays-on-the-Presocratic-Enlightenment-by-Karl-Popper.pdf
    • http://loaminoo.linkpc.net/5097096091098095/Thread-and-Gone-Mainely-Needlepoint-3-by-Lea-Wait.pdf
    • http://loaminoo.linkpc.net/5097096092090091/Tightening-the-Threads-Mainely-Needlepoint-5-by-Lea-Wait.pdf
    • http://loaminoo.linkpc.net/1091098093095090096/Needlepoint-Designs-From-Oriental-Rugs-by-Grethe-Sorensen.pdf
    • http://loaminoo.linkpc.net/8097097093091092/Karl-Schneeberg-und-das-Alte-Testament-in-Mecklenburger-Platt-by-Karl-Heinz-Madauss.pdf
    • http://loaminoo.linkpc.net/1091096098099098099/Der-F-rst-der-Bleichgesichter-Teil-1-Jubil-umsausgabe-zum-100-Todestag-von-Karl-May-by-Karl-May.pdf
    • http://loaminoo.linkpc.net/9098096096090096/Karl-May---Im-Reiche-des-silbernen-Loewen---Doppel-Band-I-und-II-by-Karl-May.pdf
    • http://loaminoo.linkpc.net/5099098095096/An-Altar-in-the-World-A-Geography-of-Faith-by-Barbara-Brown-Taylor.pdf
    • http://loaminoo.linkpc.net/1093099091099096/The-Proud-Tower-A-Portrait-of-the-World-Before-the-War-1890-1914-by-Barbara-W-Tuchman.pdf
    • http://loaminoo.linkpc.net/1090098090090096095/World-Psychiatric-Association-Symposium-on-the-Psychopathology-of-Dream-and-Sleeping-Proceedings-of-the-Symposium-by-Karl-Aimo-Achte.pdf
    • http://loaminoo.linkpc.net/1090092090098095095/Skinny-Potatoes-Over-100-delicious-new-low-fat-recipes-for-the-world-s-most-versatile-vegetable-by-Barbara-Grunes.pdf
    • http://loaminoo.linkpc.net/8098097099093093/German-Raiders