Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7cad22b5c599a6e…

MALICIOUS

PDF

16.8 KB Created: 2019-05-01 17:15:20 +01:00 Authoring application: mPDF 5.7
MD5: 17a78f3a9265b0e6502ae79fe9d78d9d SHA-1: aa86592013d4eefff8ec73f111168d43847e704a SHA-256: f7cad22b5c599a6ee816c42671781b12e6fdf53374d367f37f4bec6c58929f70
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged by a machine learning classifier and contains a large number of embedded external links, indicating a potential link farm for SEO manipulation or malicious redirection. While no scripts were extracted, the PDF structure and the sheer volume of links suggest a delivery mechanism for further malicious activity. The primary IOCs are the numerous URLs embedded within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4098093099097/The-Fundamentals-of-Long-Distance-Relationship-Things-You-Need-to-Know-About-Long-Distance-Relationships-LDR-and-Tips-How-to-Make-it-Work-by-Lisa-Daniel.pdf
    • http://loaminoo.linkpc.net/3094096093097098/Long-Distance-Life-by-Marita-Golden.pdf
    • http://loaminoo.linkpc.net/1091092093097091098/Spider-Gwen-Vol-3-Long-Distance-by-Jason-Latour.pdf
    • http://loaminoo.linkpc.net/1096090095096091/No-Distance-Left-to-Run-The-Distance-Between-Us-4-Wilde-s-6-by-L-A-Witt.pdf
    • http://loaminoo.linkpc.net/5093097094099095/True-Secrets-of-Lesbian-Desire-Keeping-Sex-Alive-in-Long-Term-Relationships-by-Renate-Stendhal.pdf
    • http://loaminoo.linkpc.net/5099096095092/A-Long-Long-Time-Ago-and-Essentially-True-by-Brigid-Pasulka.pdf
    • http://loaminoo.linkpc.net/5094096097099/Exodus-from-the-Long-Sun-The-Book-of-the-Long-Sun-4-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/7097099090094/A-Long-Long-Sleep-UniCorp-1-by-Anna-Sheehan.pdf
    • http://loaminoo.linkpc.net/1090092095090097/Litany-of-the-Long-Sun-The-Book-of-the-Long-Sun-1-2-by-Gene-Wolfe.pdf
    • http://loaminoo.linkpc.net/3092094090090092/The-Long-Utopia-The-Long-Earth-4-by-Terry-Pratchett.pdf
    • http://loaminoo.linkpc.net/4090095097090/The-Treachery-of-Beautiful-Things-by-Ruth-Frances-Long.pdf
    • http://loaminoo.linkpc.net/8090098092096/The-Color-of-Distance-by-Amy-Thomson.pdf
    • http://loaminoo.linkpc.net/1092098094099096/The-Distance-by-Saborna-Rowchowdhury.pdf
    • http://loaminoo.linkpc.net/4092098097090090/Distance-To-A-Kiss-by-Yuu-Yoshinaga.pdf
    • http://loaminoo.linkpc.net/5091097092097/Across-the-Distance-by-Marie-Meyer.pdf
    • http://loaminoo.linkpc.net/3096096090094099/Distance-by-Andrea-Heltsley.pdf
    • http://loaminoo.linkpc.net/1095094092097099/A-Long-Long-Sleep-by-Anna-Sheehan.pdf
    • http://loaminoo.linkpc.net/3092099096095098/Pulled-Long-Long-Shots-3-by-Christine-d-39-Abo.pdf
    • http://loaminoo.linkpc.net/3091099090097098/The-Long-Way-Home-by-Lisa-St-Aubin-de-Ter-n.pdf
    • http://loaminoo.linkpc.net/1090092097099092/Seasons-of-War-Long-Price-Quartet-3-4-by-Daniel-Abraham.pdf
    • http://loaminoo.linkpc.net/5094096097099/Exodus-from-the-Long-Sun-The-Book-of-