Malicious PDF — malware analysis report

Static analysis result for SHA-256 f54a9602dc8d2f57…

MALICIOUS

PDF

15.8 KB Created: 2019-05-06 16:53:38 +01:00 Authoring application: mPDF 5.7
MD5: af41e84e852a3a3065e8575fd4bca18c SHA-1: be31b0a38b0d225278ce9d46f3884d8405bc7671 SHA-256: f54a9602dc8d2f5733ab21a75f29b0118e6b6b586e7c301926467aeeb221ffab
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further payloads. The ML classifier also flagged this PDF with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9098095098094093/The-Diaries-Of-Evelyn-Waugh-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/1099093097095096/The-Loved-One-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/3099093099094/The-Loved-One-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/6095096098095/Scoop-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/5090091094091094/Scoop-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/3092093091094099/Brideshead-Revisited-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/1090097090097093093/Verfall-und-Untergang-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/7096099091090/A-Handful-of-Dust-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/9091095094095097/Ronald-Knox-A-Biography-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/9098095099095093/Evelyn-Waugh-A-Biography-by-Christopher-Sykes.pdf
    • http://loaminoo.linkpc.net/4097094094097094/Love-Among-the-Ruins-A-Romance-of-the-Near-Future-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/9098095098091093/The-Letters-of-Nancy-Mitford-and-Evelyn-Waugh-by-Charlotte-Mosley.pdf
    • http://loaminoo.linkpc.net/9098095098091091/Mad-World-Evelyn-Waugh-and-the-Secrets-of-Brideshead-by-Paula-Byrne.pdf
    • http://loaminoo.linkpc.net/9096099091092095/Tod-in-Hollywood-Eine-anglo-amerikanische-Trag-die-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/7094095095096097/Ninety-Two-Days-A-Journey-In-Guiana-And-Brazil-1932-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/2098095091091091/Brideshead-Revisited-The-Sacred-and-Profane-Memories-of-Captain-Charles-Ryder-by-Evelyn-Waugh.pdf
    • http://loaminoo.linkpc.net/6098099096097091/Reframing-the-Practice-of-Philosophy-Bodies-of-Color-Bodies-of-Knowledge-by-George-Yancy.pdf
    • http://loaminoo.linkpc.net/3093092098095095/Tea-and-Green-Ribbons-Evelyn-s-Story-by-Evelyn-Doyle.pdf
    • http://loaminoo.linkpc.net/1090095094095090096/Despotic-Bodies-and-Transgressive-Bodies-Spanish-Culture-from-Francisco-Franco-to-Jesus-Franco-by-Tatjana-Pavlovi-.pdf
    • http://loaminoo.linkpc.net/1091093091090095095/Tragic-Beauty-The-Lost-1914-Memoirs-of-Evelyn-Nesbit-by-Evelyn-Nesbit.pdf