Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcdb5d097a8d7125…

MALICIOUS

PDF

18.3 KB Created: 2019-05-02 17:51:12 +01:00 Authoring application: mPDF 5.7
MD5: b7dc59a97833bda4d8d98a9cfef3a056 SHA-1: 2fbd68c49e692b07c281e385f0def887ad728da3 SHA-256: fcdb5d097a8d71251c119eaa279d9aaf13c3999292eae0da36d62e5cffcbd80a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the document body is heavily obfuscated, the presence of numerous links suggests an attempt to manipulate search engine results or distribute malicious content. The ML_NYX_PDF_MALICIOUS heuristic further supports the malicious nature of the file. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8097094090094096/Erik-Lundberg-Studies-in-Economic-Instability-and-Change-by-Erik-Lundberg.pdf
    • http://loaminoo.linkpc.net/4093093092090093/The-Red-Address-Book-by-Sofia-Lundberg.pdf
    • http://loaminoo.linkpc.net/1095096097091094/Camille-by-Louise-Lundberg-Claesen.pdf
    • http://loaminoo.linkpc.net/8097093099092098/Cracks-In-The-Constitution-by-Ferdinand-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097093099094091/LONTAR-1-by-Jason-Erik-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097093099093095/The-Rockefeller-Syndrome-by-Ferdinand-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097093097090097/Cracks-in-the-Constitution-by-Ferdinand-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097094090094092/Politicians-and-Other-Scoundrels-by-Ferdinand-Lundberg.pdf
    • http://loaminoo.linkpc.net/2091093097093091/Red-Dot-Irreal-by-Jason-Erik-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097094090094099/Kla-Judrikis-No-Ohsolakalna-Pee-Deewaatsihschanas-Nahze-by-Lundberg.pdf
    • http://loaminoo.linkpc.net/4090093093095098/The-Time-Traveler-s-Son-by-Jason-Erik-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097094090091090/Swedish-Christmas-Crafts-by-Helene-S-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097094090095093/On-Guard-Seven-Safeguards-to-Protect-Your-Sexual-Purity-by-Gary-B-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097093099092096/Love-that-Lasts-Fourteen-Secrets-to-a-More-Joyful-Passionate-and-Fulfilling-Marriage-by-Gary-B-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097094090090096/Unifying-Truths-of-the-World-s-Religions-Practical-Principles-for-Living-and-Loving-in-Peace-by-C-David-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097093099093098/Medieval-Inspired-Knits-Stunning-Brocade-amp-Swirling-Vine-Patterns-with-Embellished-Borders-by-Anna-Karin-Lundberg.pdf
    • http://loaminoo.linkpc.net/8097093097090099/The-Book-of-Shiatsu-A-Complete-Guide-to-Using-Hand-Pressure-and-Gentle-Manipulation-to-Improve-Your-Health-Vitality-and-Stamina-by-Paul-Lundberg.pdf
    • http://loaminoo.linkpc.net/1096099090092098/The-Rich-and-the-Super-Rich-A-Study-in-the-Power-of-Money-Today-by-Ferdinand-Lundberg.pdf
    • http://loaminoo.linkpc.net/4093094092099093/7g-by-Debbie-Kump.pdf
    • http://loaminoo.linkpc.net/8090097090093098/After-Your-First-5k-by-Debbie-Voiles.pdf
    • http://loaminoo.linkpc.net/8097094090091090/Swedish-Christmas-Crafts-by-Helene-S-