Malicious PDF — malware analysis report

Static analysis result for SHA-256 4394ca0048032ecb…

MALICIOUS

PDF

13.9 KB Created: 2019-04-30 17:32:13 +01:00 Authoring application: mPDF 5.7
MD5: e2fca52bc6990cc421106296368bb361 SHA-1: bfb1fa7751bf8be75bb69c0f917e9bf15ee31d9b SHA-256: 4394ca0048032ecbdbb14abbdc2d42f88b5e3bf84dd97918ee90c1e3a0e8ffca
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, hosted on the domain loaminoo.linkpc.net. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.n
    • http://loaminoo.linkpc.net/6091091094092098/Special-by-Georgia-Blain.pdf
    • http://loaminoo.linkpc.net/1097093091095096/Between-a-Wolf-and-a-Dog-by-Georgia-Blain.pdf
    • http://loaminoo.linkpc.net/6091091095095096/Snake-in-the-Grass-by-Georgia-Blain.pdf
    • http://loaminoo.linkpc.net/1095097093092096/Births-Deaths-Marriages-by-Georgia-Blain.pdf
    • http://loaminoo.linkpc.net/1098095094097099/Drums-and-Shadows-Survival-Studies-among-the-Georgia-Coastal-Negroes-by-Georgia-Writers-39-Project.pdf
    • http://loaminoo.linkpc.net/9096092091098/Georgia-in-Hawaii-When-Georgia-O-Keeffe-Painted-What-She-Pleased-by-Amy-Novesky.pdf
    • http://loaminoo.linkpc.net/4099096097096093/Georgia-A-Novel-of-Georgia-O-Keeffe-by-Dawn-Tripp.pdf
    • http://loaminoo.linkpc.net/1095097094096095/By-Divine-Right-The-Darkwater-Saga-0-5-by-Patrick-W-Carr.pdf
    • http://loaminoo.linkpc.net/3092096091095095/The-Ember-Blade-The-Darkwater-Legacy-1-by-Chris-Wooding.pdf
    • http://loaminoo.linkpc.net/3094093090094091/The-Ember-Blade-The-Darkwater-Legacy-1-by-Chris-Wooding.pdf
    • http://loaminoo.linkpc.net/3092096094099095/Georgia-O-Keeffe-One-Hundred-Flowers-by-Georgia-O-39-Keeffe.pdf
    • http://loaminoo.linkpc.net/8095090095098098/Riopelle-by-Brad-Blain.pdf
    • http://loaminoo.linkpc.net/6091091095096090/Tales-of-the-Winter-Wolf-Vol-2-by-R-J-Blain.pdf
    • http://loaminoo.linkpc.net/6091091094099094/Blain-s-Woods-by-W-Wesley-Miller.pdf
    • http://loaminoo.linkpc.net/6091091095097090/I-Love-You-Near-and-Far-by-Marjorie-Blain-Parker.pdf
    • http://loaminoo.linkpc.net/6091091095093092/Witch-s-Blood-by-William-Blain.pdf
    • http://loaminoo.linkpc.net/6091091095094092/Games-for-All-Occasions-by-Mary-E-Blain.pdf
    • http://loaminoo.linkpc.net/6091091093098098/Beneath-a-Blood-Moon-by-R-J-Blain.pdf
    • http://loaminoo.linkpc.net/6091091095095098/Your-Kind-of-Mommy-by-Marjorie-Blain-Parker.pdf
    • http://loaminoo.linkpc.net/6091091094099098/When-Dads-Don-t-Grow-Up-by-Marjorie-Blain-Parker.pdf