Malicious PDF — malware analysis report

Static analysis result for SHA-256 e64c92f9ecb0a213…

MALICIOUS

PDF

23.6 KB Created: 2019-05-02 19:17:08 +01:00 Authoring application: mPDF 5.7
MD5: 55442dbb46ce20f685963b771a9769cb SHA-1: 4d3fb0351079b0fda76bfae772271e1e844e6dfc SHA-256: e64c92f9ecb0a213510d214c6078cc1cb19772a55154236f817b4f87c667b14a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, that masquerade as academic physics books. These links all point to the same domain, loaminoo.linkpc.net, suggesting a coordinated effort to direct users to potentially malicious content. No scripts were extracted from this sample, and the document body was not sufficiently readable to determine a specific lure beyond the link farm.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090090090098094090/Physics-for-the-Ib-Diploma-Coursebook-by-K-A-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090090098094091/Physics-for-the-Ib-Diploma-Coursebook-Enhanced-Digital-Edition-by-K-A-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090090098097095/Physics-for-the-Ib-Diploma-Exam-Preparations-Guide-by-K-A-Tsokos.pdf
    • http://loaminoo.linkpc.net/1091093090090094098/The-Physics-Book-From-the-Big-Bang-to-Quantum-Resurrection-250-Milestones-in-the-History-of-Physics-by-Clifford-A-Pickover.pdf
    • http://loaminoo.linkpc.net/6096093093096/For-the-Love-of-Physics-From-the-End-of-the-Rainbow-to-the-Edge-of-Time---A-Journey-Through-the-Wonders-of-Physics-by-Walter-Lewin.pdf
    • http://loaminoo.linkpc.net/4094097094094096/Categories--On-the-Beauty-of-Physics-Essential-Physics-Concepts-and-Their-Companions-in-Art-amp-Literature-by-Emiliano-Sefusatti.pdf
    • http://loaminoo.linkpc.net/6092090091098099/A-Guide-to-Physics-Problems-Part-2-Thermodynamics-Statistical-Physics-and-Quantum-Mechanics-by-Sidney-B-Cahn.pdf
    • http://loaminoo.linkpc.net/1090094096090096093/Psychology-for-the-Ib-Diploma-Study-Guide-by-Jette-Hannibal.pdf
    • http://loaminoo.linkpc.net/7097094092097092/Tips-on-Physics-A-Problem-solving-Supplement-to-the-Feynman-Lectures-on-Physics-by-Richard-Feynman.pdf
    • http://loaminoo.linkpc.net/1091099095093091095/Digital-Diploma-Mills-The-Automation-of-Higher-Education-by-David-F-Noble.pdf
    • http://loaminoo.linkpc.net/1090090091090095098/Complement-in-Autoimmunity-by-George-C-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090090098093099/Forensic-Pathology-Reviews-5-by-Michael-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090090098097091/Forensic-Pathology-Reviews-Vol-4-by-Michael-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090090098094093/Forensic-Pathology-Reviews-Vol-3-by-Michael-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090090099092099/Forensic-Pathology-Reviews-Vol-6-by-Michael-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090091090096095/Forensic-Pathology-Reviews-by-Michael-Tsokos.pdf
    • http://loaminoo.linkpc.net/6091096099095092/Dark-Matter-in-Astrophysics-and-Particle-Physics-1998-Proceedings-of-the-Second-International-Conference-on-Dark-Matter-in-Astro-and-Particle-Physics-Held-in-Heidelberg-Germany-20-25-July-1998-by-Hans-Volker-Klapdor-Kleingrothaus.pdf
    • http://loaminoo.linkpc.net/1090090091090095095/Computational-Methods-for-Modeling-of-Nonlinear-Systems-by-Chris-P-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090090098097099/The-Joy-of-Statistics-Learning-with-Real-World-Data---CD-by-Chris-Tsokos.pdf
    • http://loaminoo.linkpc.net/1090090090099094095/Theory-amp-Application-of-Reliability-With-Emphasis-on-Bayesian-amp-Nonparametric-Methods-2-by-Chris-P-Tsokos.pdf
    • http://loaminoo.linkpc.net/4094097094094096/Categories--On-the-Beauty-of-Physics-