Malicious PDF — malware analysis report

Static analysis result for SHA-256 f4e87471be5dafc7…

MALICIOUS

PDF

20.1 KB Created: 2019-04-30 01:43:04 +01:00 Authoring application: mPDF 5.7
MD5: 2240309ecf8d960842ac3cff99dacbb2 SHA-1: 69f1fb9841ecf5f0da84b699c980f609e914a423 SHA-256: f4e87471be5dafc78ab2fd85595740ce4742e2b8be80e462d7958e2c348bcea0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links to external PDF files hosted on 'loaminoo.linkpc.net'. This technique, identified as a PDF SEO link farm, is often used to distribute malware or redirect users to phishing websites. While no scripts were extracted, the sheer volume of links suggests a high likelihood of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1092091092091097/Morris-As-Elvis-The-World-s-Greatest-Elvis-Impersonator-by-Morris-Bates.pdf
    • http://loaminoo.linkpc.net/3094090093094094/Elvis-by-Elvis-Presley.pdf
    • http://loaminoo.linkpc.net/1090092094099099095/The-First-William-Morris-Omnibus-The-House-of-the-Wolflings-The-Well-at-the-World-s-End-Wood-Beyond-the-World-by-William-Morris.pdf
    • http://loaminoo.linkpc.net/7092095094099090/The-Speeches-of-Mr-Ross-and-Mr-Morris-Delivered-in-the-Senate-of-the-United-States-by-Gouverneur-Morris.pdf
    • http://loaminoo.linkpc.net/7092095094097097/Diary-and-Letters-of-Gouverneur-Morris-Volume-1-by-Anne-Cary-Morris.pdf
    • http://loaminoo.linkpc.net/1094092090093092/Tommy-s-Honor-The-Story-of-Old-Tom-Morris-and-Young-Tom-Morris-Golf-s-Founding-Father-and-Son-by-Kevin-Cook.pdf
    • http://loaminoo.linkpc.net/7092095094098099/An-Answer-By-G-Morris-to-J-Stephen-s-War-in-Disguise-by-Gouverneur-Morris.pdf
    • http://loaminoo.linkpc.net/7092095094098097/The-Diary-and-Letters-of-Gouverneur-Morris-Minister-of-the-United-States-to-France-Volume-2-by-Gouverneur-Morris.pdf
    • http://loaminoo.linkpc.net/6096091091092099/News-from-Nowhere-or-an-Epoch-of-Rest-Being-Some-Chapters-from-a-Utopian-Romance-1890-by-William-Morris-by-William-Morris.pdf
    • http://loaminoo.linkpc.net/6090098093099098/To-Secure-the-Blessings-of-Liberty-Selected-Writings-of-Gouverneur-Morris-by-Gouverneur-Morris.pdf
    • http://loaminoo.linkpc.net/2090091093090094/Biggest-Elvis-by-P-F-Kluge.pdf
    • http://loaminoo.linkpc.net/1097098093092097/Elvis-and-the-Underdogs-by-Jenny-Lee.pdf
    • http://loaminoo.linkpc.net/5094096098092/Dragon-Path-Collected-Tales-of-Kenneth-Morris-by-Kenneth-Morris.pdf
    • http://loaminoo.linkpc.net/8095090097092092/The-Search-For-Elvis-by-William-Riopelle.pdf
    • http://loaminoo.linkpc.net/3090091090094096/The-Gospel-Side-of-Elvis-by-Joe-Moscheo.pdf
    • http://loaminoo.linkpc.net/1090090096091093091/Bitter-Melon-by-Elvis-Alves.pdf
    • http://loaminoo.linkpc.net/1095098090092099/The-Well-At-The-World-s-End-Volume-I-by-William-Morris.pdf
    • http://loaminoo.linkpc.net/9097094091095095/Elvis-The-Boy-Who-Dared-To-Rock-by-Paul-Lichter.pdf
    • http://loaminoo.linkpc.net/4092098093098/The-Forgotten-Man-Elvis-Cole-10-by-Robert-Crais.pdf
    • http://loaminoo.linkpc.net/4092098094094097/A-Lawyer-s-Journey-The-Morris-Dees-Story-by-Morris-Dees.pdf
    • http://loaminoo.linkpc.net/709209509