Malicious PDF — malware analysis report

Static analysis result for SHA-256 48d71d2974ad2a9f…

MALICIOUS

PDF

15.3 KB Created: 2019-04-30 17:45:32 +01:00 Authoring application: mPDF 5.7
MD5: b61b983fb32a69058ba7cde1f28f5238 SHA-1: 9780f61fd3e70d4f3b5356c0c1f51516c3f0d67e SHA-256: 48d71d2974ad2a9f6e764cb09f2d60741bb297c2b027750138df45a9de179c63
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file was flagged by an ML classifier as malicious and contains a large number of embedded external links, a technique often used for SEO poisoning or to distribute further malicious content. While the document body itself is not readable, the heuristic 'PDF_SEO_LINK_FARM' indicates a suspicious pattern of linking to numerous PDF files hosted on 'loaminoo.linkpc.net'. The presence of these links suggests an attempt to lure users to malicious sites or to manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093096096096093/The-Ant-Heap-A-Novel-by-Margit-Kaffka.pdf
    • http://loaminoo.linkpc.net/1095096092091093/Septimus-Heap-Box-Set-Magyk-and-Flyte-Septimus-Heap-1-2-by-Angie-Sage.pdf
    • http://loaminoo.linkpc.net/1091095095090097094/A-Patchwork-Christmas-Margit-Echols-by-Margit-Echols.pdf
    • http://loaminoo.linkpc.net/8098098093097093/388-Great-Hairstyles-by-Margit-Rudiger.pdf
    • http://loaminoo.linkpc.net/4091094095092097/D-dens-have-Sagaen-om-Isfolket-17-by-Margit-Sandemo.pdf
    • http://loaminoo.linkpc.net/1091099090092090091/Bis-dass-der-Tod-euch-scheidet-Roman-by-Margit-Steeger.pdf
    • http://loaminoo.linkpc.net/1091095095090094092/Fate-of-Ravens-Margit-Andersson-2-by-Tiina-Nunnally.pdf
    • http://loaminoo.linkpc.net/9099094097094098/Ausgeschlossen-Ein-Monolog-in-zehn-Szenen-by-Margit-Koemeda.pdf
    • http://loaminoo.linkpc.net/9093097096099093/Migrants-and-Cities-The-Accommodation-of-Migrant-Organizations-in-Europe-by-Margit-Fauser.pdf
    • http://loaminoo.linkpc.net/9097091097097095/Intelligente-Emotionalit-t-Vom-Umgang-mit-unseren-Gef-hlen-by-Margit-Koemeda-Lutz.pdf
    • http://loaminoo.linkpc.net/1091098092097098094/Personal-Property-Wives-White-Slaves-and-the-Market-in-Women-by-Margit-Stange.pdf
    • http://loaminoo.linkpc.net/1091098097098095092/Franzi---Eine-Mutter-k-mpft-gegen-den-unsichtbaren-Feind-by-Margit-Steeger.pdf
    • http://loaminoo.linkpc.net/1091093097090091094/Old-Heap-The-by-Alvin-Fick.pdf
    • http://loaminoo.linkpc.net/1091093096096096092/Behind-the-Facade-by-Victoria-Heap.pdf
    • http://loaminoo.linkpc.net/1096094094094090/Cowboy-Baby-by-Sue-Heap.pdf
    • http://loaminoo.linkpc.net/1091093096097096090/Danny-s-Drawing-Book-by-Sue-Heap.pdf
    • http://loaminoo.linkpc.net/1091093096096090095/A-Heap-O-Livin-by-Edgar-A-Guest.pdf
    • http://loaminoo.linkpc.net/1091093096098093091/A-Heap-of-Trouble-by-Elizabeth-Messenger.pdf
    • http://loaminoo.linkpc.net/1091093096098094091/The-Ash-Heap-of-History-by-Chris-Morgan.pdf
    • http://loaminoo.linkpc.net/1090093098095097098/K-he-essen-Wiese-auf-und-andere-Wahrheiten-f-r-Leute-die-aufs-Land-wollen-by-Margit-Sch-nberger.pdf
    • http://loaminoo.linkpc.net/9097091097097095/Intelligente-Emotional