Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7cd54c8a89dd3b7…

MALICIOUS

PDF

15.4 KB Created: 2019-04-30 17:30:20 +01:00 Authoring application: mPDF 5.7
MD5: 1c4c76cf85d74e310f7d40967c6738fa SHA-1: e83a8ef32d8894ad0df35afeb3c5dc27c7877f95 SHA-256: c7cd54c8a89dd3b74670d102529731df720a8e43995c5b621fc47b3402dd4a35
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, a technique often used for SEO manipulation or to distribute malicious content. The ML classifier strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure or payload. The primary IOCs are the numerous URLs hosted on loaminoo.linkpc.net.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096098099094094/Choices-Choices-1-by-Sydney-Lane.pdf
    • http://loaminoo.linkpc.net/4090093097093095/Courier-from-Warsaw-by-Jan-Nowak.pdf
    • http://loaminoo.linkpc.net/5091090094091099/Diana-s-Electric-Tongue-by-Carolyn-Nowak.pdf
    • http://loaminoo.linkpc.net/6099095096094098/Walker-s-Carnivores-of-the-World-by-Ronald-M-Nowak.pdf
    • http://loaminoo.linkpc.net/1090096093093096091/Mother-s-Curse-Book-1-by-Thaddeus-Nowak.pdf
    • http://loaminoo.linkpc.net/3093097093099094/Three-More-Nick-Nowak-Mysteries-Boystown-2-by-Marshall-Thornton.pdf
    • http://loaminoo.linkpc.net/1092098090098095/Evolving-Ecstasy-Almost-Human-The-First-Trilogy-3-by-Melanie-Nowak.pdf
    • http://loaminoo.linkpc.net/1093096091095095/Descendant-of-Darkness-ALMOST-HUMAN-The-Second-Trilogy-Volume-2-by-Melanie-Nowak.pdf
    • http://loaminoo.linkpc.net/9090096097092092/Moment-A-Practical-Guide-to-Creating-a-Mindful-Life-in-a-Distracted-World-by-Achim-Nowak.pdf
    • http://loaminoo.linkpc.net/8097099092096096/Writing-for-Children-Pamela-Cleaver-by-Pamela-Cleaver.pdf
    • http://loaminoo.linkpc.net/9096093097096099/Der-gro-e-Gold-Insider-Report-In-Gold-investiren-lohnt-immer-Edelmetalle-mit-System-by-Dennis-Nowak.pdf
    • http://loaminoo.linkpc.net/4097091093097096/Choices-by-Deborah-Lynn-Jacobs.pdf
    • http://loaminoo.linkpc.net/1096098099097096/Hope-Choices-3-by-Sydney-Lane.pdf
    • http://loaminoo.linkpc.net/1096098099099099/Fate-Choices-2-by-Sydney-Lane.pdf
    • http://loaminoo.linkpc.net/4091099098094090/Unplanned-Choices-by-Frank-E-Hopkins.pdf
    • http://loaminoo.linkpc.net/2099090091097091/Killer-Choices-1-by-Edward-Bettin-Jr-.pdf
    • http://loaminoo.linkpc.net/1094095094092094/Never-A-Choice-The-Choices-Trilogy-1-by-Dee-Palmer.pdf
    • http://loaminoo.linkpc.net/1094095094097091/Always-A-Choice-Choices-Trilogy-2-by-Dee-Palmer.pdf
    • http://loaminoo.linkpc.net/3093098092091091/The-Choices-We-Make-by-Karma-Brown.pdf
    • http://loaminoo.linkpc.net/1097096097090097/Choices-Waiting-for-Forever-1-by-Jamie-Mayfield.pdf
    • http://loaminoo.linkpc.net/9096093097096099/Der-gro-e-Gold-Insider-Report-In-Gold-investiren-lo