Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a6b531b5cfeebad…

MALICIOUS

PDF

20.8 KB Created: 2019-05-02 17:35:36 +01:00 Authoring application: mPDF 5.7
MD5: d696cf0b0333e2fd8f0217e510c444e5 SHA-1: 07ceb9935844cd7a3c2fa0cafba393c2e8ae5a9e SHA-256: 4a6b531b5cfeebadf4aa57622f3d90dc60204c080fe2f5801b936f0a7d927017
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the loaminoo.linkpc.net domain. This is indicative of a link farm or SEO poisoning attack, designed to drive traffic to potentially malicious or unwanted content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9092098091091099/Weaving-Designs-by-Bertha-Gray-Hayes-Miniature-Overshot-Patterns-by-Weavers-Guild-of-Rhode-Island.pdf
    • http://loaminoo.linkpc.net/1091098090099095099/Stress-Relieving-Adult-Book-Coloring-Designs-Peaceful-Patterns-Featuring-Mandala-and-Mind-Calming-Designs-with-Henna-Inspired-Flowers-by-Dorothy-Mohl.pdf
    • http://loaminoo.linkpc.net/4099099092094090/Weaving-the-Visions-New-Patterns-in-Feminist-Spirituality-by-Judith-Plaskow.pdf
    • http://loaminoo.linkpc.net/2091095099094096/Rhode-Island-Blues-by-Fay-Weldon.pdf
    • http://loaminoo.linkpc.net/1095095091097090/Searching-for-Rhode-Island-by-Dawn-M-Porter.pdf
    • http://loaminoo.linkpc.net/9099091099091095/Designs-for-Holbein-embroidery-110-new-geometric-patterns-by-Nikki-Scheuer.pdf
    • http://loaminoo.linkpc.net/5097099093091094/Don-Bousquet-s-Rhode-Island-Cookbook-by-Martha-Watson-Murphy.pdf
    • http://loaminoo.linkpc.net/1091092099099093095/Environmental-Monitoring-and-Remediation-III-28-30-October-2003-Providence-Rhode-Island-USA-by-Society-of-Photo-optical-Instrumentation-Engineers.pdf
    • http://loaminoo.linkpc.net/6091092098090090/New-England-Regional-Atlas-amp-Gazetteer-s-Connecticut-Rhode-Island-Massachusetts-Maine-New-Hampshire-and-Vermont-Atlases-by-DeLorme-Mapping-Company.pdf
    • http://loaminoo.linkpc.net/4096099099096090/The-Universe-in-Miniature-in-Miniature-by-Patrick-Somerville.pdf
    • http://loaminoo.linkpc.net/3091090094093094/Bertha-Size-Your-Life-The-Bertha-Series-Book-1-by-Jane-Carroll.pdf
    • http://loaminoo.linkpc.net/9092097097099096/Becoming-Bertha-The-Bertha-Series-Book-2-by-Jane-Carroll.pdf
    • http://loaminoo.linkpc.net/7094092096092096/Patterns-Revealed-Patterns-3-by-Suede-Delray.pdf
    • http://loaminoo.linkpc.net/7094092096097099/More-Patterns-Patterns-2-by-Suede-Delray.pdf
    • http://loaminoo.linkpc.net/2096098095093090/The-Animal-Guild-Animal-Guild-1-by-Jennifer-Sowle.pdf
    • http://loaminoo.linkpc.net/3096092093094093/Hollywood-Days-with-Hayes-by-Hayes-Grier.pdf
    • http://loaminoo.linkpc.net/9096092093092091/Crochet-For-Beginners-Make-such-Awesome-Crochet-Patterns-amp-Stitches-that-No-One-Will-Believe-You-Did-Crochet-Patterns-Crochet-Stiches-Crochet-Books-by-Sheila-Lawson.pdf
    • http://loaminoo.linkpc.net/2099090090/Death-Weavers-Five-Kingdoms-4-by-Brandon-Mull.pdf
    • http://loaminoo.linkpc.net/1092093099099091/Weavers-The-Frost-Chronicles-3-by-Kate-Avery-Ellison.pdf
    • http://loaminoo.linkpc.net/6098090093094099/Sired-by-Stone-The-Fabrick-Weavers-2-by-Andrew-Post.pdf
    • http://loaminoo.linkpc.net/1095095091097090/Searching-for-Rhode-Island-by-Dawn-M-Porter