Malicious PDF — malware analysis report

Static analysis result for SHA-256 2040a71cd4e8e32e…

MALICIOUS

PDF

21.8 KB Created: 2019-04-30 04:07:07 +01:00 Authoring application: mPDF 5.7
MD5: f0e2debb8fb352c258a0c419f3e91ed2 SHA-1: ebeaf20450109583d653711824bd5cb1bb7e2639 SHA-256: 2040a71cd4e8e32e47b1382287311192f6fbc0e419eeecd6e5cb7c335bbe2a68
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. While the specific intent of the links is unclear due to the 'confirmed_benign' labels on some, the sheer volume and the heuristic firing suggest a malicious purpose, possibly to redirect users to phishing sites or download further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6091097095091/Being-In-Balance-9-Principles-for-Creating-Habits-to-Match-Your-Desires-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/1091098091099099095/Excuses-Begone-How-to-Change-Lifelong-Self-Defeating-Thinking-Habits-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/8094090094096093/Creating-Balance-A-Self-Reflective-Book-to-Bring-More-Energy-Productivity-and-Balance-into-Your-Life-by-Alene-Baronian-MS-RDN.pdf
    • http://loaminoo.linkpc.net/5099093091096/Gifts-from-Eykis-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/8090093092092092/Pensees-inspirantes-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/9096098095098/Living-the-Wisdom-of-the-Tao-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/9091093099091/10-Secrets-for-Success-and-Inner-Peace-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/7093091098097092/A-New-Way-of-Thinking-A-New-Way-of-Being-Experiencing-the-Tao-Te-ching-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/9091092097097/Everyday-Wisdom-Trade-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/2090095092098090/The-Sensitive-s-Circle-Finding-Balance-amp-Creating-Hope-by-Michael-Sortomme.pdf
    • http://loaminoo.linkpc.net/9091091096098/Wisdom-of-the-Ages-60-Days-to-Enlightenment-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/3092091090098091/Wishes-Fulfilled-Mastering-the-Art-of-Manifesting-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/5096098094093/The-Shift-Taking-Your-Life-from-Ambition-to-Meaning-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/7091096099097090/La-fuerza-de-creer-You-ll-see-it-when-you-believe-it-C-mo-cambiar-su-vida-The-Way-to-Your-Personal-Transformation-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/5097092093091098/Major-Principles-of-Media-Law-2013-Edition-by-Wayne-Overbeck.pdf
    • http://loaminoo.linkpc.net/9094097091094094/Ayurveda-Beginner-s-Guide-Essential-Ayurvedic-Principles-amp-Practices-to-Balance-amp-Heal-Naturally-by-Susan-Weis-Bohlen.pdf
    • http://loaminoo.linkpc.net/5097090098092090/Time-Habitude-Warriors-Principles-to-Master-Your-Time-Habits-by-Erik-Swanson.pdf
    • http://loaminoo.linkpc.net/3092092091090095/The-Secret-Missing-Links-of-the-Law-of-Attraction-The-Habits-That-Keep-You-Poor-and-a-Step-by-Step-Guide-to-Conquer-Them-and-Get-the-Life-You-Rightly-Deserve-by-Wayne-Evans.pdf
    • http://loaminoo.linkpc.net/8092094097090090/The-New-Gold-Standard-5-Leadership-Principles-for-Creating-a-Legendary-Customer-Experience-Courtesy-of-the-Ritz-Carlton-Hotel-Company-by-Joseph-A-Michelli.pdf
    • http://loaminoo.linkpc.net/9090093093/Atomic-Habits-An-Easy-amp-Proven-Way-to-Build-Good-Habits-amp-Break-Bad-Ones-by-James-Clear.pdf