Malicious PDF — malware analysis report

Static analysis result for SHA-256 f59ebe367e8b4a24…

MALICIOUS

PDF

19.8 KB Created: 2019-05-02 07:29:33 +01:00 Authoring application: mPDF 5.7
MD5: 3784880de43f3386e8a5c06b2094c80f SHA-1: ac8d95fd363af38bbfaa9bbcdb0cd2c2a626db50 SHA-256: f59ebe367e8b4a2417dc9d109515f8d75ec4153929e5bd884c9c3a3e0a3a5745
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external websites, identified by the PDF_SEO_LINK_FARM heuristic. While the specific URLs appear benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5094097096095091/Enter-Helen-The-Invention-of-Helen-Gurley-Brown-and-the-Rise-of-the-Modern-Single-Woman-by-Brooke-Hauser.pdf
    • http://loaminoo.linkpc.net/2095091095090091/Tumbledown-Manor-by-Helen-Brown.pdf
    • http://loaminoo.linkpc.net/5090096099098098/Women-of-the-World-The-Rise-of-the-Female-Diplomat-by-Helen-McCarthy.pdf
    • http://loaminoo.linkpc.net/1097091091098099/The-Rancher-s-Woman-by-Helen-Karol.pdf
    • http://loaminoo.linkpc.net/8096095094094097/The-Hussy-s-Handbook-by-Helen-Brown-Norden.pdf
    • http://loaminoo.linkpc.net/3095094095099098/The-Good-Life-Helen-and-Scott-Nearing-s-Sixty-Years-of-Self-Sufficient-Living-by-Helen-Nearing.pdf
    • http://loaminoo.linkpc.net/2095095093094098/Lady-Helen-and-the-Dark-Days-Club-Lady-Helen-1-by-Alison-Goodman.pdf
    • http://loaminoo.linkpc.net/4091097097098095/Polar-Dream-The-First-Solo-Expedition-by-a-Woman-and-Her-Dog-to-the-Magnetic-North-Pole-by-Helen-Thayer.pdf
    • http://loaminoo.linkpc.net/3099095090094098/Answer-Me-This-by-Helen-Zaltzman-Olly-Mann-by-Helen-Zaltzman.pdf
    • http://loaminoo.linkpc.net/6090093093098092/To-Love-This-Life-Quotations-By-Helen-Keller-by-Helen-Keller.pdf
    • http://loaminoo.linkpc.net/8090094097099/A-Widow-s-Tale-The-1884-1896-Diary-of-Helen-Mar-Kimball-Whitney-Life-Writings-of-Frontier-Women-Vol-6-Life-Writings-of-Frontier-Women-by-Helen-Mar-Whitney.pdf
    • http://loaminoo.linkpc.net/6093096090097/T-ngata-Ng-i-Tahu-People-of-Ng-i-Tahu-by-Helen-Brown.pdf
    • http://loaminoo.linkpc.net/4095092097092099/Rise-Sister-Rise-A-Guide-to-Unleashing-the-Wise-Wild-Woman-Within-by-Rebecca-Campbell.pdf
    • http://loaminoo.linkpc.net/9094094096099096/Kaspar-Hauser-A-Modern-Metaphor-by-Ursula-Sampath.pdf
    • http://loaminoo.linkpc.net/1091098092094097097/Spoiling-for-a-Fight-The-Rise-of-Eliot-Spitzer-by-Brooke-A-Masters.pdf
    • http://loaminoo.linkpc.net/1091091098093092091/A-Woman-of-Worth-Talitha-Cumi-Woman-Arise-by-Jacquelyn-Brown-Hadnot.pdf
    • http://loaminoo.linkpc.net/3099094097092099/The-End-of-Tomorrow-The-Single-Lady-Spy-3-by-Tara-Brown.pdf
    • http://loaminoo.linkpc.net/2097099093093091/All-the-Single-Ladies-Unmarried-Women-and-the-Rise-of-an-Independent-Nation-by-Rebecca-Traister.pdf
    • http://loaminoo.linkpc.net/3094095094095093/Confessions-Of-A-Single-Black-Woman-by-D-T-Pollard.pdf
    • http://loaminoo.linkpc.net/5096098095092094/The-Single-Proverbs-31-Woman-by-Alice-Giraud.pdf
    • http://loaminoo.linkpc.net/4091097097098095/Polar-Dream-The-First-Solo-Expedition-by-a-Woman-and-Her