Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7f4afe2d12b8f3f…

MALICIOUS

PDF

21.3 KB Created: 2019-04-30 03:46:54 +01:00 Authoring application: mPDF 5.7
MD5: 33bb024da5ead42ae8828ce4a9874fd4 SHA-1: 4db26b88440efb951897779b109bedc65b4ae7c1 SHA-256: f7f4afe2d12b8f3f14241dba14eb4a08a758f4654c0e5510852f79ed2835172a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs that form a link farm, likely for SEO manipulation. The primary purpose appears to be directing users to external content hosted on loaminoo.linkpc.net, rather than delivering a direct payload. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091095098092099090/Kindle-User-s-Guide-by-Amazon.pdf
    • http://loaminoo.linkpc.net/1091098091093093097/Amazon-Echo-Amazon-Echo-Advanced-User-Guide-2016-Updated-Echo-Amazon-Echo-User-Manual-Amazon-Alexa-Amazon-Echo-Dot-Amazon-Echo-ebook-by-Jamy-Jackson.pdf
    • http://loaminoo.linkpc.net/1091098091093097090/Amazon-Dot-Newbie-to-Expert-in-60-Minutes-on-Amazon-Dot-2nd-Generation-Echo-Amazon-Echo-User-Manual-Amazon-Alexa-Amazon-Echo-Dot-Amazon-Echo-ebook-Book-3-by-Jamy-Jackson.pdf
    • http://loaminoo.linkpc.net/3097095093091090/The-Kindle-Publishing-Bible-How-to-Sell-More-Kindle-eBooks-on-Amazon-by-Tom-Corson-Knowles.pdf
    • http://loaminoo.linkpc.net/9098093095091095/The-Ultimate-Guide-For-Starting-an-Amazon-Kindle-Publishing-Business-Step-By-Step-Instructions-How-To-Publish-A-Book-Promote-It-And-Make-Sales-by-Liudas-Butkus.pdf
    • http://loaminoo.linkpc.net/3092091097098090/Publish-on-Amazon-Kindle-with-Kindle-Direct-Publishing-by-Kindle-Direct-Publishing.pdf
    • http://loaminoo.linkpc.net/9096094094093/Free-Books-For-Kindle-Linked-List-Of-Over-1-000-Free-Fiction-Classics-For-Download-As-Free-Kindle-Books-From-Amazon-by-Morris-Rosenthal.pdf
    • http://loaminoo.linkpc.net/9099091094099/Get-Your-Book-Published-on-Kindle-Amazon-by-Sandratana-Camille.pdf
    • http://loaminoo.linkpc.net/1091094094092099090/Amazon-Prime-Learn-Everything-About-Amazon-Prime-A-Complete-Guide-by-Ivan-Peretti.pdf
    • http://loaminoo.linkpc.net/1091093092098093091/ipad-user-guide-for-iOS-8-1-by-Apple-Inc-.pdf
    • http://loaminoo.linkpc.net/2097096091092090/A-User-s-Guide-to-Neglectful-Parenting-by-Guy-Delisle.pdf
    • http://loaminoo.linkpc.net/8093095093090099/Hug---Human-User-Guide-by-Chris-Dollard.pdf
    • http://loaminoo.linkpc.net/2097091096094098/You-Are-Here-A-User-s-Guide-to-the-Universe-by-Richard-Farr.pdf
    • http://loaminoo.linkpc.net/4090096096091091/The-Direct-Path-A-User-Guide-by-Greg-Goode.pdf
    • http://loaminoo.linkpc.net/1090091095092095093/Voodoo-Rituals-A-User-s-Guide-by-Heike-Owusu.pdf
    • http://loaminoo.linkpc.net/1090091099092097090/Worldchanging-A-User-s-Guide-for-the-21st-Century-by-Alex-Steffen.pdf
    • http://loaminoo.linkpc.net/2092096099091/The-User-s-Guide-to-Being-Human-The-Art-and-Science-of-Self-by-Scott-Edmund-Miller.pdf
    • http://loaminoo.linkpc.net/6093097090091092/Dust-and-Fume-Control-A-User-Guide-by-Gulf-Publishing-Co.pdf
    • http://loaminoo.linkpc.net/3095092099097099/Nerdy-Shy-and-Socially-Inappropriate-A-User-Guide-to-an-Asperger-Life-by-Cynthia-Kim.pdf
    • http://loaminoo.linkpc.net/2095091092097096/Amazon-Seller-Central-Secrets-Use-Amazon-Profits-to-fire-your-boss-BYOB-1-by-Bruce-Walker.pdf
    • http://loaminoo.linkpc.net/1091098091093097090/Amazon