Malicious PDF — malware analysis report

Static analysis result for SHA-256 4393f1c871a9e119…

MALICIOUS

PDF

15.1 KB Created: 2019-04-30 02:39:51 +01:00 Authoring application: mPDF 5.7
MD5: c053c4b734ba4c3ea7a8a2c51064a7d8 SHA-1: f4c3b2e1c06f5fed3e3971ed21fa823d2c07d3fb SHA-256: 4393f1c871a9e1193999a94e28a21db9f464f76b27aa42f56b22d724b145f6e1
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'loaminoo.linkpc.net'. This is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted, and the document body was heavily corrupted, preventing a deeper analysis of the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091090096098091098/Cerebral-Localization-An-Otfrid-Foerster-Symposium-by-Otfrid-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096099099093/Foerster-Amer-P-amp-P-Vol-1-amp-2-Combo-5ed-by-Michael-H-Foerster.pdf
    • http://loaminoo.linkpc.net/9097098097090091/Einf-hrung-in-das-Werk-Walthers-von-der-Vogelweide-by-Otfrid-Ehrismann.pdf
    • http://loaminoo.linkpc.net/1091090098095097093/Einf-hrung-in-das-Werk-Walthers-von-der-Vogelweide-by-Otfrid-Ehrismann.pdf
    • http://loaminoo.linkpc.net/1091090096099091092/Big-Boobs-Sex-Stories-by-Erik-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096098093093/The-Burning-of-Troy-by-Richard-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096099098094/Algebra-And-Trigonometry-by-Paula-A-Foerster.pdf
    • http://loaminoo.linkpc.net/1091098097095090/River-Road-by-Richard-Foerster.pdf
    • http://loaminoo.linkpc.net/1091096093099098092/Erstaunliche-Fickgeschichten-by-Erik-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096098092091/Calculus-Concepts-and-Applications-by-Paul-A-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090097090090091/Algebra-I-Teacher-s-Edition-by-Paul-A-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096099098098/Algebra-and-Trigonometry-Teacher-s-Edition-by-Paul-A-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096096093098/Lost-Ancient-Technology-Of-Egypt-by-Brien-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096097093098/Financial-Management-Concepts-and-Applications-by-Stephen-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096096094090/Algebra-and-Trigonometry-Functions-and-Applications-by-Paul-A-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096099091094/Introduction-to-American-Poetry-and-Prose-by-Norman-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096098093091/Hidden-in-the-Trees-An-Isle-Royale-Sojourn-by-Vic-Foerster.pdf
    • http://loaminoo.linkpc.net/1090099092091097093/Gartengestaltung-mit-Stauden-Von-Foerster-bis-New-German-Style-by-Mascha-Schacht.pdf
    • http://loaminoo.linkpc.net/1091090096097093099/FOERSTER-ALGEBRA-AND-TRIGONOMETRY-SKILLS-PRACTICE-by-Addison-Wesley.pdf
    • http://loaminoo.linkpc.net/1091090096096096095/Writing-and-Thinking-A-Handbook-of-Composition-and-Revision-by-Norman-Foerster.pdf
    • http://loaminoo.linkpc.net/1091090096099098098/Algebra-and-Trigonometry-Teacher-s-Editio