Malicious PDF — malware analysis report

Static analysis result for SHA-256 df56051f2a61956d…

MALICIOUS

PDF

17.6 KB Created: 2019-04-30 17:27:12 +01:00 Authoring application: mPDF 5.7
MD5: f6bbd281e15280f739ff8b542d559af0 SHA-1: 1926cc7ca15ccb8f6505c1ec3871d8fed5af82a0 SHA-256: df56051f2a61956d6e625057ad6cb6e57d689fdf683ee5ed6bc3f549ce93ae1f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large farm of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a malicious intent to manipulate search engine results or redirect users. While the document body is heavily obfuscated, the presence of numerous links to what appear to be book titles on the 'linkpc.net' domain indicates a potential lure or redirection scheme. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095096091095096/Through-These-Eyes-Blind-Faith-2-by-N-R-Walker.pdf
    • http://loaminoo.linkpc.net/3099093096099090/Blind-Faith-Blind-Faith-1-by-N-R-Walker.pdf
    • http://loaminoo.linkpc.net/2094093093098090/Blind-Sight-Through-the-Eyes-of-Leocardo-Reyes-Blind-Sight-1-Leocardo-by-Ermisenda-Alvarez.pdf
    • http://loaminoo.linkpc.net/3091090099094097/Blind-Faith-by-Teresa-Gabelman.pdf
    • http://loaminoo.linkpc.net/3098090098090097/Blind-Trust-With-Open-Eyes-by-Dinor-Adam-V-Levi.pdf
    • http://loaminoo.linkpc.net/7090093095099/Blind-Faith-Sin-Brothers-3-by-Rebecca-Zanetti.pdf
    • http://loaminoo.linkpc.net/7096094099096091/Nirvana-Moksha-and-Blind-Faith-Not-Expected---Pamphlet-by-Helena-Petrovna-Blavatsky.pdf
    • http://loaminoo.linkpc.net/4099096095095096/Blind-Redemption-Blind-3-by-Violetta-Rand.pdf
    • http://loaminoo.linkpc.net/7092097097097090/3x3-Eyes-Descent-of-the-Mystic-City-3x3-Eyes-8-by-Yuzo-Takada.pdf
    • http://loaminoo.linkpc.net/4097095090096099/Rachel-s-Eyes-Eyes-of-Silver-Revisited-1-by-Ellen-O-39-Connell.pdf
    • http://loaminoo.linkpc.net/3091093092097094/One-Eye-Two-Eyes-Three-Eyes-A-Hutzul-Tale-by-Eric-A-Kimmel.pdf
    • http://loaminoo.linkpc.net/1092095091099095/Phantom-Eyes-Witch-Eyes-3-by-Scott-Tracey.pdf
    • http://loaminoo.linkpc.net/5093098091096091/Unlocking-the-Patmos-Code-by-Walker-William-Walker.pdf
    • http://loaminoo.linkpc.net/1095090094092091/Meeting-Faith-The-Forest-Journals-of-a-Black-Buddhist-Nun-by-Faith-Adiele.pdf
    • http://loaminoo.linkpc.net/2097092093093095/From-Faith-To-Faith-A-Daily-Guide-To-Victory-by-Kenneth-Copeland.pdf
    • http://loaminoo.linkpc.net/7090099097093097/Understanding-the-Faith-A-Workbook-for-Communicants-Classes-and-Others-Preparing-to-Make-a-Public-Confession-of-Faith-by-Stephen-Smallman.pdf
    • http://loaminoo.linkpc.net/7092091095093090/Fight-of-the-Walker-The-Walker-3-by-Coralee-June.pdf
    • http://loaminoo.linkpc.net/1090094094094097095/Everyday-Faith-Practical-Essays-on-Personal-Faith-and-the-Ethical-Choices-We-Face-in-Daily-Life-by-Terry-Pluto.pdf
    • http://loaminoo.linkpc.net/3091090093097095/Beyond-the-Eyes-Beyond-the-Eyes-1-by-Rebekkah-Ford.pdf
    • http://loaminoo.linkpc.net/5093093094094096/The-Temple-of-the-Blind-The-Temple-of-the-Blind-3-by-Brian-Harmon.pdf
    • http://loaminoo.linkpc.net/7092097097097090/3x3-Eyes-Descent-of-the-Mystic-City-3x3-Eyes-8-by-Yuzo-Takada.p