Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e8471f26ef2b112…

MALICIOUS

PDF

18.3 KB Created: 2019-05-02 01:44:43 +01:00 Authoring application: mPDF 5.7
MD5: ba069622949c8574aa41fcd15ab0f509 SHA-1: 8a46d56a3b0e4734a9e19ecf61416acd2b6b2782 SHA-256: 3e8471f26ef2b11252d6559f208e845a4eaf9134ff723446af8c03ed0b162ba3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links to external PDF files hosted on loaminoo.linkpc.net. This indicates a likely SEO link farm or a distribution mechanism for further malicious content. The embedded URLs are the primary IOCs. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7096090090094093/Encyclopedia-Kaczynski-Volume-10C-by-Guinevere-Maltese.pdf
    • http://loaminoo.linkpc.net/7096090091092093/Encyclopedia-Kaczynski-Volume-1D-by-Guinevere-Maltese.pdf
    • http://loaminoo.linkpc.net/7096090090094099/Encyclopedia-Kaczynski-Volume-6-by-Guinevere-Maltese.pdf
    • http://loaminoo.linkpc.net/7096090090094091/Encyclopedia-Kaczynski-Volume-9-by-Guinevere-Maltese.pdf
    • http://loaminoo.linkpc.net/3091092094093094/Guinevere-A-Medieval-Romance-Guinevere-1-3-by-Lavinia-Collins.pdf
    • http://loaminoo.linkpc.net/4095094090095094/Desperate-and-Deceptive-The-Guinevere-Jones-Collection-Volume-1-by-Jayne-Castle.pdf
    • http://loaminoo.linkpc.net/6093094095092099/The-Maltese-the-Maltese-Dog-by-Anna-Katherine-Nicholas.pdf
    • http://loaminoo.linkpc.net/6093097093092/The-Encyclopedia-of-Immaturity-Volume-2-by-Klutz.pdf
    • http://loaminoo.linkpc.net/9099091097098093/Encyclopedia-of-Philosophy-10-Volume-Set-by-Donald-M-Borchert.pdf
    • http://loaminoo.linkpc.net/5092092095097090/Encyclopedia-of-Bioethics-Volume-4-Race-to-Zygote-by-Warren-T-Reich.pdf
    • http://loaminoo.linkpc.net/5092092095096098/Encyclopedia-of-Bioethics-Volume-3-Medical-to-Quality-by-Warren-T-Reich.pdf
    • http://loaminoo.linkpc.net/8092093094091092/Geosophia-The-Argo-of-Magic-Encyclopedia-Goetica-Volume-II-by-Jake-Stratton-Kent.pdf
    • http://loaminoo.linkpc.net/2095097095093094/Building-the-World-An-Encyclopedia-of-the-Great-Engineering-Projects-in-History-Volume-1-by-Frank-Davidson.pdf
    • http://loaminoo.linkpc.net/1097095095094095/Encyclopedia-Brown-and-the-Case-of-the-Secret-Pitch-Encyclopedia-Brown-2-by-Donald-J-Sobol.pdf
    • http://loaminoo.linkpc.net/1091094091090099090/Encyclopedia-Brown-and-the-Case-of-the-Slippery-Salamander-Encyclopedia-Brown-22-by-Donald-J-Sobol.pdf
    • http://loaminoo.linkpc.net/1091094091090099092/Encyclopedia-Brown-and-the-Case-of-the-Two-Spies-Encyclopedia-Brown-19-by-Donald-J-Sobol.pdf
    • http://loaminoo.linkpc.net/1091094091090094097/Encyclopedia-Brown-Takes-the-Case-Encyclopedia-Brown-10-by-Donald-J-Sobol.pdf
    • http://loaminoo.linkpc.net/1090090094092091098/Encyclopedia-Brown-Sets-The-Pace-Encyclopedia-Brown-15-by-Donald-J-Sobol.pdf
    • http://loaminoo.linkpc.net/1090095092096093/The-Words-in-My-Hand-by-Guinevere-Glasfurd.pdf
    • http://loaminoo.linkpc.net/1094097095096091/Encyclopedia-Brown-Keeps-the-Peace-Encyclopedia-Brown-6-by-Donald-J-Sobol.pdf
    • http://loaminoo.linkpc.net/8092093094091092/Geosophia-The-Argo-of-Magic-Encyclopedia-Goetica-Volume-II-by-Jake-Stratton-Kent.pd