Malicious PDF — malware analysis report

Static analysis result for SHA-256 ace7e60bb2fa6d52…

MALICIOUS

PDF

25.0 KB Created: 2019-05-01 17:32:45 +01:00 Authoring application: mPDF 5.7
MD5: d37b4d3ebd2faf4263bd72b0254ab3d5 SHA-1: bce1d514cc659c79a41451a5a931f907271df91b SHA-256: ace7e60bb2fa6d5267a897ec138730908759fdd7398f7dff0649c85d78e734df
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file was flagged by a machine learning classifier and contains a large number of external links, indicating a potential SEO manipulation or content distribution scheme. The embedded URLs, such as http://loaminoo.linkpc.net/9097090092091093/Essay-approach-to-addiction-pharmacology-Chemical-Treatment-for-Behaviors-by-Fredy-Martinez.pdf, are likely used to redirect users to malicious sites or download further payloads. No scripts were extracted, but the structure and link farm suggest a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9906

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9097090092091093/Essay-approach-to-addiction-pharmacology-Chemical-Treatment-for-Behaviors-by-Fredy-Martinez.pdf
    • http://loaminoo.linkpc.net/7099097090094096/Integral-Recovery-A-Revolutionary-Approach-to-the-Treatment-of-Alcoholism-and-Addiction-by-John-Dupuy.pdf
    • http://loaminoo.linkpc.net/9097090092092096/Casino-and-Gambling-Addiction-by-Fredy-Zarate.pdf
    • http://loaminoo.linkpc.net/1099092098096094/Relapse-Prevention-Maintenance-Strategies-in-the-Treatment-of-Addictive-Behaviors-by-G-Alan-Marlatt.pdf
    • http://loaminoo.linkpc.net/1090096096092095091/Integrated-Pharmacology-Combining-Modern-Pharmacology-with-Chinese-Medicine-by-Greg-Sperber.pdf
    • http://loaminoo.linkpc.net/9097090090091091/Chemthermo-A-Statistical-Approach-to-Classical-Chemical-Thermodynamics-by-Leonard-Kollender-Nash.pdf
    • http://loaminoo.linkpc.net/1091093097093091093/Handbook-of-Orthognathic-Treatment-A-Team-Approach-by-Ashraf-Ayoub.pdf
    • http://loaminoo.linkpc.net/3098096091095099/Treatment-of-Complex-Trauma-A-Sequenced-Relationship-Based-Approach-by-Christine-A-Courtois.pdf
    • http://loaminoo.linkpc.net/2093099091092091/Staying-Well-in-a-Toxic-World-Understanding-Environmental-Illness-Multiple-Chemical-Sensitivities-Chemical-Injuries-and-Sick-Building-Syndrome-by-Lynn-Lawson.pdf
    • http://loaminoo.linkpc.net/2099091095092096/Addiction-Recovery-DIY-Do-it-Yourself---Conquer-Your-Drug-or-Alcohol-Addiction-at-Home-by-K-J-Gordon.pdf
    • http://loaminoo.linkpc.net/7093099093099091/The-life-beyond-Drug-Addiction-A-comprehensive-self-help-guide-from-identifying-addiction-to-recovery-process-by-Joanes-Comia.pdf
    • http://loaminoo.linkpc.net/2099091097098097/Slaying-The-Addiction-Monster-An-All-Inclusive-Look-At-Drug-Addiction-In-America-Today-by-Sheryl-Letzgus-McGinnis.pdf
    • http://loaminoo.linkpc.net/7096095090092096/Sugar-Addiction-How-to-Overcome-a-Sugar-Addiction-the-Natural-Way-by-Gabby-Roles.pdf
    • http://loaminoo.linkpc.net/1090091094093095091/Self-Treatment-for-Drug-Abuse-Self-Treatment-for-Drug-Abuse-Learn-All-About-Self-Treatment-for-Drug-Abuse-by-sami-yaak.pdf
    • http://loaminoo.linkpc.net/5094099095096098/Principles-of-Pharmacology-by-H-L-Sharma.pdf
    • http://loaminoo.linkpc.net/8099099095091091/Pharmacology-by-Christopher-Herz.pdf
    • http://loaminoo.linkpc.net/5098094090099092/Chemistry-and-Pharmacology-of-Anticancer-Drugs-by-David-Thurston.pdf
    • http://loaminoo.linkpc.net/8092095092094092/Pharmacology-And-Therapeutics-In-Respiratory-Care-by-Theodore-J-Witek.pdf
    • http://loaminoo.linkpc.net/6093091094094094/AIDS-to-Clin-Pharmacology-Therapeutcs-3e-by-Jonathan-Reese.pdf
    • http://loaminoo.linkpc.net/9099098090/Sweet-Addiction-Sweet-Addiction-1-by-J-Daniels.pdf
    • http://loaminoo.linkpc.net/1