Malicious PDF — malware analysis report

Static analysis result for SHA-256 f85b226e1b54f9e0…

MALICIOUS

PDF

22.8 KB Created: 2019-04-30 02:55:30 +01:00 Authoring application: mPDF 5.7
MD5: e147e7244169f30134de4ebb0eb8151a SHA-1: e2ac17c9110862342f504abf35d66124944095db SHA-256: f85b226e1b54f9e016451a7dc251c1f99584c8600e2e0cef1995d6f537ea05df
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the dynamic DNS domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the immediate user-facing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091098091099099095/Excuses-Begone-How-to-Change-Lifelong-Self-Defeating-Thinking-Habits-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/6091097095091/Being-In-Balance-9-Principles-for-Creating-Habits-to-Match-Your-Desires-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/7093091098097092/A-New-Way-of-Thinking-A-New-Way-of-Being-Experiencing-the-Tao-Te-ching-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/8093099095092094/Baby-Self-Feeding-Solutions-for-Introducing-Purees-and-Solids-to-Create-Lifelong-Healthy-Eating-Habits-by-Nancy-Ripton.pdf
    • http://loaminoo.linkpc.net/7098094098096/How-Successful-People-Think-Change-Your-Thinking-Change-Your-Life-by-John-C-Maxwell.pdf
    • http://loaminoo.linkpc.net/9096098095098/Living-the-Wisdom-of-the-Tao-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/5099093091096/Gifts-from-Eykis-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/8090093092092092/Pensees-inspirantes-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/9091092097097/Everyday-Wisdom-Trade-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/9091093099091/10-Secrets-for-Success-and-Inner-Peace-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/3092091090098091/Wishes-Fulfilled-Mastering-the-Art-of-Manifesting-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/9091091096098/Wisdom-of-the-Ages-60-Days-to-Enlightenment-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/5096098094093/The-Shift-Taking-Your-Life-from-Ambition-to-Meaning-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/7096097094092/Transforming-Faith-Stories-of-Change-from-a-Lifelong-Spiritual-Seeker-by-Fred-Howard.pdf
    • http://loaminoo.linkpc.net/4098098097092096/Hungry-for-Change-Ditch-the-Diets-Conquer-the-Cravings-and-Eat-Your-Way-to-Lifelong-Health-by-James-Colquhoun.pdf
    • http://loaminoo.linkpc.net/7091096099097090/La-fuerza-de-creer-You-ll-see-it-when-you-believe-it-C-mo-cambiar-su-vida-The-Way-to-Your-Personal-Transformation-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/3092097091098/The-7-Habits-of-Highly-Effective-People-Powerful-Lessons-in-Personal-Change-by-Stephen-R-Covey.pdf
    • http://loaminoo.linkpc.net/3092092091090095/The-Secret-Missing-Links-of-the-Law-of-Attraction-The-Habits-That-Keep-You-Poor-and-a-Step-by-Step-Guide-to-Conquer-Them-and-Get-the-Life-You-Rightly-Deserve-by-Wayne-Evans.pdf
    • http://loaminoo.linkpc.net/9098093096097/Change-Your-Thinking-Overcome-Stress-Anxiety-and-Depression-and-Improve-Your-Life-with-CBT-by-Sarah-Edelman.pdf
    • http://loaminoo.linkpc.net/5092090092095099/Ready-Thinking---Primed-For-Change-5-Principles-For-Action-In-Times-Of-Uncertainty-by-John-Baker.pdf
    • http://loaminoo.linkpc.net/7098094098096/How-Succe