Malicious PDF — malware analysis report

Static analysis result for SHA-256 d60cb2058df56363…

MALICIOUS

PDF

20.2 KB Created: 2019-04-30 17:23:09 +01:00 Authoring application: mPDF 5.7
MD5: 2fd828b38c11c34d3b7fa342ab139b40 SHA-1: 6dd6eeeec019894dc9115f1d05a7ef4d7dc8a138 SHA-256: d60cb2058df563637bb4ff65a86dd8862d5f8a6efcf21af840c9ab3df64ae4e9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded links, identified as a PDF_SEO_LINK_FARM heuristic, pointing to various PDF documents hosted on loaminoo.linkpc.net. While the document body is heavily obfuscated and unreadable, the presence of numerous external links suggests a distribution or SEO manipulation tactic. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.lin
    • http://loaminoo.linkpc.net/2097093098094097/Goddess-Test-Goddess-Interrupted-The-Goddess-Legacy-The-Goddess-Inheritance-Goddess-Test-1-3-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/3093096092092/The-Goddess-Test-Goddess-Test-1-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/2097094090094097/The-Goddess-Test-Goddess-Test-1-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/3096092090094097/The-Goddess-Test-Goddess-Test-1-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/3094097097095095/Goddess-of-the-Underworld-Goddess-Test-2-5C-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/3098092091093/The-Goddess-Legacy-Goddess-Test-2-5-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/2095092090098099/Goddess-Interrupted-Goddess-Test-2-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/3094097097095097/The-Lovestruck-Goddess-Goddess-Test-2-5B-by-Aimee-Carter.pdf
    • http://loaminoo.linkpc.net/2091098090094093/F-this-Test-Even-More-of-the-Very-Best-Totally-Wrong-Test-Answers-by-Richard-Benson.pdf
    • http://loaminoo.linkpc.net/1090093099090092092/Eyes-Open-Sex-Domestic-Goddess-to-Sex-Goddess-by-Fiona-Chatterley.pdf
    • http://loaminoo.linkpc.net/7091094092096090/Heka-s-Blessing-A-modern-goddess-of-ancient-Egypt-Goddess-of-the-Black-Land-Book-1-by-Alexandria-Grolleau.pdf
    • http://loaminoo.linkpc.net/4094091091093092/Goddess-of-the-Rose-Goddess-Summoning-Series-4-by-P-C-Cast.pdf
    • http://loaminoo.linkpc.net/4096098093093093/Wrath-of-the-Goddess-The-Goddess-s-Saga-2-by-Maria-Hammarblad.pdf
    • http://loaminoo.linkpc.net/3098094095094/Goddess-of-Light-Goddess-Summoning-3-by-P-C-Cast.pdf
    • http://loaminoo.linkpc.net/2090097098095091/Goddess-of-Spring-Goddess-Summoning-2-by-P-C-Cast.pdf
    • http://loaminoo.linkpc.net/4097091090092098/Goddess-of-the-Rose-Goddess-Summoning-4-by-P-C-Cast.pdf
    • http://loaminoo.linkpc.net/4096098096097099/Oh-My-Goddess-22-Oh-My-Goddess-22-by-Kosuke-Fujishima.pdf
    • http://loaminoo.linkpc.net/7099099091090091/Integrated-Advanced-Microwave-Sounding-Unit-A-Amsu-A-Engineering-Test-Report-Radiated-Emissions-and-Sarr-Sarp-Dcs-Receivers-Link-Frequencies-EMI-Sensitive-Band-Test-Results-Amsu-A1-S-N-109-by-National-Aeronaut-Administration-Nasa-.pdf
    • http://loaminoo.linkpc.net/2095098098097095/The-Complete-America-s-Test-Kitchen-TV-Show-Cookbook-2001-2010-by-America-39-s-Test-Kitchen.pdf
    • http://loaminoo.linkpc.net/3099090098093097/Erin-the-Fire-Goddess-The-Beginning-Erin-the-Fire-Goddess-1-by-Lavinia-Urban.pdf