Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc7c56d4f68fe4a9…

MALICIOUS

PDF

22.7 KB Created: 2019-05-02 01:31:27 +01:00 Authoring application: mPDF 5.7
MD5: 0eee8dfb1e54cf0e62db4807cff9ba18 SHA-1: f7a5329a3b034cad92df31e6647c2324319619f5 SHA-256: fc7c56d4f68fe4a9e7d968f9ee5b0427f0ef87b74c1a8017979a0fea82707376
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. While many of these URLs are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkp
    • http://loaminoo.linkpc.net/3092094093090098/The-Father-s-Cabin-Kingdom-Living-series-Book-1-by-Cheryl-Olson.pdf
    • http://loaminoo.linkpc.net/5094094098094098/Brandon-Mull-Series-Reading-Order-amp-Checklist-Series-List-in-Order---Five-Kingdom-Series-Fablehaven-Series-Beyonders-Trilogy-Candy-Shop-War-Series-Listabook-Series-Order-Book-24-by-Listabook.pdf
    • http://loaminoo.linkpc.net/1096091093093092/Articles-on-Old-Kingdom-Series-Including-Sabriel-Lirael-Abhorsen-Across-the-Wall-A-Tale-of-the-Abhorsen-and-Other-Stories-Old-Kingdom-Book-Ser-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/1091098092094093091/Living-in-the-Shadows-The-Foundling-s-Path---Part-1-Linmore-Series-Book-4-by-Jemima-Brigges.pdf
    • http://loaminoo.linkpc.net/3097099091091090/The-Cabin-Books-The-Cabin-and-The-Asylum-by-Matt-Shaw.pdf
    • http://loaminoo.linkpc.net/4094092098092094/Kingdom-Hearts-The-Complete-Series-Kingdom-Hearts-1-4-by-Shiro-Amano.pdf
    • http://loaminoo.linkpc.net/1093093095097094/Orson-Scott-Card-Series-Reading-Order-amp-Checklist-Series-List-in-Order---Ender-Series-Formic-War-Series-Shadow-Series-Ender-Series-amp-Tales-of-Alvin-Maker-Series-Listabook-Series-Order-Book-15-by-Listabook.pdf
    • http://loaminoo.linkpc.net/1090095094092096/Henry-s-Demons-Living-with-Schizophrenia-A-Father-and-Son-s-Story-by-Patrick-Cockburn.pdf
    • http://loaminoo.linkpc.net/2097093090091092/Cabin-Fever-Hot-Winter-Nights-Book-1-by-Audra-North.pdf
    • http://loaminoo.linkpc.net/6091092095097092/The-Cabin-The-Manhattan-Stories-Book-3-by-Donna-Foley-Mabry.pdf
    • http://loaminoo.linkpc.net/1096099098096096/The-Hollow-Kingdom-The-Hollow-Kingdom-Trilogy-Book-I-by-Clare-B-Dunkle.pdf
    • http://loaminoo.linkpc.net/7091096092099096/Maya-Banks-Series-Reading-Order-amp-Checklist-Series-List-in-Order---KGI-Series-Enforcers-Series-Slow-Burn-Series-amp-All-Other-Books-Listabook-Series-Order-Book-58-by-Listabook.pdf
    • http://loaminoo.linkpc.net/9099094098096097/Cheryl-Brisco-s-Book-of-Confidence-by-Cheryl-Brisco.pdf
    • http://loaminoo.linkpc.net/5099094092097097/After-Oil-The-Kingdom-of-Walden-Series-1-by-Kristan-Cannon.pdf
    • http://loaminoo.linkpc.net/4098091098093099/Transgression-The-Kingdom-Come-Series-1-by-Brandy-Ange.pdf
    • http://loaminoo.linkpc.net/3094091094093090/His-Father-s-Command-The-Quest-of-Faith-Series-1-by-Justus-A-Platt.pdf
    • http://loaminoo.linkpc.net/1091099096096095099/Sins-of-the-Father-Runaway-Girl-Series-3-by-Emily-Organ.pdf
    • http://loaminoo.linkpc.net/5099094092097095/Between-Silence-and-Fire-The-Kingdom-of-Walden-Series-3-by-Kristan-Cannon.pdf
    • http://loaminoo.linkpc.net/5099094092097096/The-Last-Iron-Horse-The-Kingdom-of-Walden-Series-2-by-Kristan-Cannon.pdf
    • http://loaminoo.linkpc.net/8095092099095094/Grammar-Sense-2-Student-Book-2-by-Cheryl-Pavlik.pdf