Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd4140b2b9f3687c…

MALICIOUS

PDF

19.0 KB Created: 2019-05-07 02:57:11 +01:00 Authoring application: mPDF 5.7
MD5: 0239b1426ad13eac0c67e4a69fd3491e SHA-1: 927c7a7b613cc69289881caebf598c00ba1aa315 SHA-256: fd4140b2b9f3687cd4008f7ea12de3fd325c8d36156ab69e7b14b3e3c6e84ed4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the ML classifier also flagged it as malicious, the specific intent beyond link farming is unclear due to the lack of executable scripts or a discernible document body. The primary IOCs are the URLs hosted on loaminoo.linkpc.net, which are likely used for SEO manipulation or to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095098091096099/The-Cold-War-An-International-History-by-David-Painter.pdf
    • http://loaminoo.linkpc.net/5090095097093097/Miss-Frost-Solves-A-Cold-Case-A-Nocturne-Falls-Mystery-Jayne-Frost-1-by-Kristen-Painter.pdf
    • http://loaminoo.linkpc.net/1098099095091094/David-Jones-Engraver-Soldier-Painter-Poet-by-Thomas-Dilworth.pdf
    • http://loaminoo.linkpc.net/2097099090097093/The-Earth-Painter-Painter-1-by-Melissa-Turner-Lee.pdf
    • http://loaminoo.linkpc.net/1091091094097093094/Textiles-of-the-Low-Countries-in-European-Economic-History-Proceedings-of-the-Tenth-International-Economic-History-Congress-Leuven-August-1990-Session-B-15-by-Eric-Aerts.pdf
    • http://loaminoo.linkpc.net/5097094094094/The-Cold-War-A-History-by-Martin-Walker.pdf
    • http://loaminoo.linkpc.net/3090094093093092/The-Cold-War-A-Military-History-by-Robert-Cowley.pdf
    • http://loaminoo.linkpc.net/7096093099092094/The-Oxford-Handbook-of-the-History-of-International-Law-by-Bardo-Fassbender.pdf
    • http://loaminoo.linkpc.net/1091098095091098094/The-Marvellous-History-of-the-Shadowless-Man-And-the-Cold-Heart-by-Adelbert-von-Chamisso.pdf
    • http://loaminoo.linkpc.net/9090094098098092/The-Cold-War-A-History-in-Documents-and-Eyewitness-Accounts-by-Jussi-M-Hanhim-ki.pdf
    • http://loaminoo.linkpc.net/1091096098096091095/International-Logistics-by-Pierre-A-David.pdf
    • http://loaminoo.linkpc.net/7091098097098090/The-World-s-Key-Industry-History-and-Economics-of-International-Shipping-by-Gelina-Harlaftis.pdf
    • http://loaminoo.linkpc.net/5090096099093092/Napoleon-s-Wars-An-International-History-1803-1815-by-Charles-Esdaile.pdf
    • http://loaminoo.linkpc.net/1090098095094092099/A-Tale-of-The-Cat-Painter-05-A-Tale-of-The-Cat-Painter-5-by-Nagao-Maru.pdf
    • http://loaminoo.linkpc.net/1091097091091090090/The-Triumph-of-the-Dark-European-International-History-1933-1939-by-Zara-S-Steiner.pdf
    • http://loaminoo.linkpc.net/9099092099095092/Spheres-of-Influence-in-International-Relations-History-Theory-and-Politics-by-Susanna-Hast.pdf
    • http://loaminoo.linkpc.net/7099094091098094/Political-Theories-of-International-Relations-From-Thucydides-to-the-Present-by-David-Boucher.pdf
    • http://loaminoo.linkpc.net/9093091093092090/Zurich-International-Chess-Tournament-1953-by-David-Ionovich-Bronstein.pdf
    • http://loaminoo.linkpc.net/2098099098097097/Dumbing-of-Age-Volume-6-The-Machinations-of-My-Revenge-Will-Be-Cold-Swift-and-Absolutely-Ridiculous-by-David-Willis.pdf
    • http://loaminoo.linkpc.net/8092098090094090/Civilising-Criminal-Justice-An-International-Restorative-Agenda-for-Penal-Reform-by-David-J-Cornwell.pdf
    • http://loaminoo.linkpc.net/3090094093093092/The-Cold-War-A-Military-History-by-Robert-Cowle