Malicious PDF — malware analysis report

Static analysis result for SHA-256 7fc27ab06652057d…

MALICIOUS

PDF

24.1 KB Created: 2019-04-30 04:19:57 +01:00 Authoring application: mPDF 5.7
MD5: a2b55478aa6c896698b646dd764fdc2b SHA-1: 9b68df3f4427d32075e40a5e103b42aedbbde210 SHA-256: 7fc27ab06652057dbb84bd23c9e4ffb792c1f03fc85d1ad8f2b405446704314c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary heuristic identified a 'PDF_SEO_LINK_FARM' with 28 links, predominantly hosted on 'loaminoo.linkpc.net', suggesting a coordinated effort to direct users to potentially harmful content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7099090098091095/Inverse-Problem-Theory-by-Albert-Tarantola.pdf
    • http://loaminoo.linkpc.net/7099090096090097/Parameter-Estimation-and-Inverse-Problems-by-Brian-Borchers.pdf
    • http://loaminoo.linkpc.net/7099090096091092/Parameter-Estimation-and-Inverse-Problems-by-Richard-C-Aster.pdf
    • http://loaminoo.linkpc.net/6091096092091095/Mixing-Methods-in-Psychology-The-Integration-of-Qualitative-and-Quantitative-Methods-in-Theory-and-Practice-by-Zazie-Todd.pdf
    • http://loaminoo.linkpc.net/7099090096091095/Methods-for-Solving-Inverse-Problems-in-Mathematical-Physics-by-A-I-Prilepko.pdf
    • http://loaminoo.linkpc.net/1091098095094099092/A-differential-item-functioning-model-for-testlet-based-items-using-a-bi-factor-multidimensional-item-response-theory-model-A-Bayesian-approach-by-Hirotaka-Fukuhara.pdf
    • http://loaminoo.linkpc.net/1090093097090093091/Calibration-and-Parameterization-Methods-for-the-Libor-Market-Model-by-Christoph-Hackl.pdf
    • http://loaminoo.linkpc.net/7099090097093092/Inverse-Theory-for-Petroleum-Reservoir-Characterization-and-History-Matching-by-Dean-S-Oliver.pdf
    • http://loaminoo.linkpc.net/8093097090097091/Perturbations-Theory-and-Methods-by-James-A-Murdock.pdf
    • http://loaminoo.linkpc.net/5098093093096098/Winning-Trust-and-Confidence-A-Grounded-Theory-Model-by-A-Bazin.pdf
    • http://loaminoo.linkpc.net/5096094091092092/Borel-s-Methods-of-Summability-Theory-and-Application-by-Watson-Shawyer.pdf
    • http://loaminoo.linkpc.net/1090090090099094096/The-Theory-and-Applications-of-Reliability-with-Emphasis-on-Bayesian-and-Nonparametric-Methods-by-Chris-P-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090090099094095/Theory-amp-Application-of-Reliability-With-Emphasis-on-Bayesian-amp-Nonparametric-Methods-2-by-Chris-P-Tsokos.pdf
    • http://loaminoo.linkpc.net/9092093096090090/Fundamental-Amplifier-Techniques-with-Electron-Tubes-Theory-and-Practice-with-Design-Methods-for-Self-Construction-by-Rudolf-Moers.pdf
    • http://loaminoo.linkpc.net/7095093098094090/Relativity-The-Special-and-General-Theory-w-Figures-amp-Formulas-by-Albert-Einstein.pdf
    • http://loaminoo.linkpc.net/8097091091098098/The-Model-Book-Model-werden-mit-perfekter-Modelmappe-Modelagentur-DIY---Do-it-yourself-by-Stephan-Czaja.pdf
    • http://loaminoo.linkpc.net/4092093098099090/I-m-No-Angel-From-Victoria-s-Secret-Model-to-Role-Model-by-Kylie-Bisutti.pdf
    • http://loaminoo.linkpc.net/1090096092096091099/Methods-in-Enzymology-Volume-454-Computer-Methods-Part-a-by-Michael-L-Johnson.pdf
    • http://loaminoo.linkpc.net/5093093097097097/Text-Analysis-in-Translation-Theory-Methodology-and-Didactic-Application-of-a-Model-for-Translation-Oriented-Text-Analysis-Amsterdamer-Publikationen-Zur-Sprache-Und-Literatur-94-by-Christiane-Nord.pdf
    • http://loaminoo.linkpc.net/7094094091097099/The-Estimation-Of-Probabilities-Research-Monograph-by-Irving-John-Good.pdf
    • http://loaminoo.linkpc.net/1091098095094099092/A-differential-item-functioning-model-for-testlet-based-items-using-a-