Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe2994b3f61e2b62…

MALICIOUS

PDF

16.0 KB Created: 2019-04-30 04:52:35 +01:00 Authoring application: mPDF 5.7
MD5: 2e6621c339bf3413cc006c96cd45f93a SHA-1: 556dd6ce2f77d26c325fd66818e21066272fc71f SHA-256: fe2994b3f61e2b625efd7aec4ed2436ff15d4a1b90ebf85abaf254fdcc53051b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, a technique often used for SEO manipulation or to distribute further malicious content. The primary heuristic identified a link farm hosted on 'loaminoo.linkpc.net'. While no scripts were extracted, the presence of numerous links suggests a delivery mechanism for other malicious payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8099097090091096/Captured-by-Richard-A-Matheis.pdf
    • http://loaminoo.linkpc.net/8099097090090094/Captured-A-WW-II-Experience-of-Air-Force-P-O-W-S-in-Germany-by-Richard-A-Matheis.pdf
    • http://loaminoo.linkpc.net/6093092095092/Captured-Moments-Inspiration-Captured-in-Verse-by-J-D-Estrada.pdf
    • http://loaminoo.linkpc.net/7097091097090096/He-s-Captured-my-Heart-Captured-1-by-Karen-Frances.pdf
    • http://loaminoo.linkpc.net/8099097090091097/Kai-lan-and-the-Ladybug-Festival-by-Mickie-Matheis.pdf
    • http://loaminoo.linkpc.net/8099097090090099/Babysitting-Blues-by-Mickie-Matheis.pdf
    • http://loaminoo.linkpc.net/8099097090099099/Jans-Abenteuer-by-Elisabeth-Matheis.pdf
    • http://loaminoo.linkpc.net/8099097091096098/The-Incredibles-Mad-Libs-by-Mickie-Matheis.pdf
    • http://loaminoo.linkpc.net/8099097091096099/First-Date-Mad-Libs-by-Mickie-Matheis.pdf
    • http://loaminoo.linkpc.net/8099097092096093/Edward-Scissorhands-Mad-Libs-by-Mickie-Matheis.pdf
    • http://loaminoo.linkpc.net/8099097093096096/Inverted-Edge-Tactics-How-to-cut-someone-off-of-you-by-George-F-Matheis-Jr.pdf
    • http://loaminoo.linkpc.net/5090094098098/The-Nazi-Hunters-How-a-Team-of-Spies-and-Survivors-Captured-the-World-s-Most-Notorious-Nazis-How-a-Team-of-Spies-and-Survivors-Captured-the-World-s-Most-Notorious-Nazi-by-Neal-Bascomb.pdf
    • http://loaminoo.linkpc.net/7099093096098090/Captured-by-K-E-A-Koffi.pdf
    • http://loaminoo.linkpc.net/7097091096092091/Captured-by-Neil-Cross.pdf
    • http://loaminoo.linkpc.net/1092097096099/Captured-by-Victoria-Lynne.pdf
    • http://loaminoo.linkpc.net/4096093096097/Captured-by-Jasinda-Wilder.pdf
    • http://loaminoo.linkpc.net/6098090092090098/Works-by-Richard-Matheson-Novels-by-Richard-Matheson-Screenplays-by-Richard-Matheson-Short-Stories-by-Richard-Matheson-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/3095099092093/Captured-The-Captive-1-by-Erica-Stevens.pdf
    • http://loaminoo.linkpc.net/4098093090099094/Captured-by-the-Vampire-by-Delilah-Dunn.pdf
    • http://loaminoo.linkpc.net/9090098095090091/Captured-in-Hatten-by-Glenn-Schmidt.pdf
    • http://loaminoo.linkpc.net/5090094098098/The-Nazi-Hunters-How-a-Team-of-Spies-and-Survivors-Captured-the-World-s-Most-Notorious-Nazis-How-a-Te