Malicious PDF — malware analysis report

Static analysis result for SHA-256 2040ed5a8c72c487…

MALICIOUS

PDF

29.9 KB Created: 2019-05-01 20:58:57 +01:00 Authoring application: mPDF 5.7
MD5: b9a2cab0fb8400d0a2fc99bd1535943d SHA-1: 567d38abfcff833d9295c346bdbafa3b7f47cd39 SHA-256: 2040ed5a8c72c48759ca4b620120f0ed399335952fc3c6ddf51dfa2566666a7a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier and contains a significant number of embedded external links, suggesting a link farm or redirection scheme. While the document body is unreadable, the heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, with the first one being http://loaminoo.linkpc.net/7099096095091091/Jit-Implementation-Manual-The-Complete-Guide-to-Just-In-Time-Manufacturing-by-Hiroyuki-Hirano.pdf. The overall purpose appears to be to lure users to external, potentially malicious, content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9885

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7099096095091091/Jit-Implementation-Manual-The-Complete-Guide-to-Just-In-Time-Manufacturing-by-Hiroyuki-Hirano.pdf
    • http://loaminoo.linkpc.net/7099096096091098/Jit-Implementation-Manual----The-Complete-Guide-to-Just-In-Time-Manufacturing-Volume-1----The-Just-In-Time-Production-System-by-Hiroyuki-Hirano.pdf
    • http://loaminoo.linkpc.net/7099096095090095/Jit-Is-Flow-Practice-and-Principles-of-Lean-Manufacturing-by-Hiroyuki-Hirano.pdf
    • http://loaminoo.linkpc.net/7099096094093099/Poka-Yoke-Spanish-Mejorando-La-Calidad-del-Producto-Evitando-Los-Defectos-by-Hiroyuki-Hirano.pdf
    • http://loaminoo.linkpc.net/8093095094096093/The-Mortgage-Manual-The-Complete-Guide-to-Choosing-the-Real-Estate-Loan-That-s-Best-by-Don-Debat.pdf
    • http://loaminoo.linkpc.net/2097095095092090/The-Essential-Guide-to-Writing-a-Novel-A-Complete-and-Concise-Manual-for-Fiction-Writers-by-James-Stewart-Thayer.pdf
    • http://loaminoo.linkpc.net/1091099092093095090/Solutions-Manual-To-Accompany-Introduction-To-Manufacturing-Processes-by-John-A-Schey.pdf
    • http://loaminoo.linkpc.net/1090094099094092097/The-Team-Captain-s-Leadership-Manual-The-Complete-Guide-to-Developing-Team-Leaders-Whom-Coaches-Respect-and-Teammates-Trust-by-Jeff-Janssen.pdf
    • http://loaminoo.linkpc.net/8092095094092095/The-Manga-Guide-to-Calculus-by-Hiroyuki-Kojima.pdf
    • http://loaminoo.linkpc.net/9097099090092094/SAP-R-3-Implementation-with-ASAP-The-Official-SAP-Guide-With-Contains-a-Test-Engine-for-Technical-Training-by-Hartwig-Brand.pdf
    • http://loaminoo.linkpc.net/9091096099097094/McSa-MCSE-Exchange-Server-2003-Implementation-and-Management-Study-Guide-Exam-70-284-by-Will-Schmied.pdf
    • http://loaminoo.linkpc.net/1091099092092092096/The-Entrepreneur-s-Guide-to-Sewn-Product-Manufacturing-by-Kathleen-Fasanella.pdf
    • http://loaminoo.linkpc.net/1094092098090094/The-Complete-Compost-Gardening-Guide-Banner-Batches-Grow-Heaps-Comforter-Compost-and-Other-Amazing-Techniques-for-Saving-Time-and-Money-and-Producing-the-Most-Flavorful-Nutritious-Vegetables-Ever-by-Barbara-Pleasant.pdf
    • http://loaminoo.linkpc.net/6098098095093/Dianetics-55-The-Complete-Manual-Of-Human-Communication-by-L-Ron-Hubbard.pdf
    • http://loaminoo.linkpc.net/6095091095099093/The-Complete-Manual-of-Accounting-Reports-Formats-and-Designs-by-Joel-G-Siegel.pdf
    • http://loaminoo.linkpc.net/1098094097090094/The-Complete-Idiot-s-Guide-to-Starting-a-Food-Truck-Business-Complete-Idiot-s-Guides-by-Alan-Philips.pdf
    • http://loaminoo.linkpc.net/8091096098092090/A-Time-to-Mourn-a-Time-to-Comfort-2nd-Edition-A-Guide-to-Jewish-Bereavement-by-Ron-Wolfson.pdf
    • http://loaminoo.linkpc.net/7093093093098094/Maximize-Your-Time-A-Progressive-Guide-For-Time-Management-And-Organizational-Skills-by-Rohit-Uniyal.pdf
    • http://loaminoo.linkpc.net/4094098095095099/Time-Travel-and-Warp-Drives-A-Scientific-Guide-to-Shortcuts-through-Time-and-Space-by-Allen-Everett.pdf
    • http://loaminoo.linkpc.net/1091095091092092099/The-Lipstick-Mystic-s-Guide-to-Time-Traveling-Healing-the-Time-Body-and-Finding-the-Best-Possible-Timeline-by-Jennifer-Shepherd.pdf
    • http://loaminoo.linkpc.net/7099096096091098/Jit-Implementation-Manual----The-Complete-Guide-to-Just-In-Time-Manufacturin