Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe48dd69248b1035…

MALICIOUS

PDF

21.8 KB Created: 2019-05-02 22:43:23 +01:00 Authoring application: mPDF 5.7
MD5: 27032334ec48c6fc0dac45cdc3e0fa2a SHA-1: 05fee746dc53b273f2536286736e1c3b5525a1d7 SHA-256: fe48dd69248b1035de1f396b287ed6eba34af8c877a7f16e014dd4b0dc132d8b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links, identified as a PDF SEO link farm. These links, such as http://loaminoo.linkpc.net/5092094095098096/Snakes-Guillotines-Electric-Chairs-My-Adventures-in-The-Alice-Cooper-Group-by-Dennis-Dunaway.pdf, likely serve as a lure to redirect users to potentially harmful websites or download further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5092094095098096/Snakes-Guillotines-Electric-Chairs-My-Adventures-in-The-Alice-Cooper-Group-by-Dennis-Dunaway.pdf
    • http://loaminoo.linkpc.net/2099094097096099/Alice-s-Adventures-Under-Ground-Alice-s-Adventures-in-Wonderland-0-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/6090093098099099/Alice-s-Adventures-in-Wonderland-Through-the-Looking-Glass-and-What-Alice-Found-There-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/6090097093092094/Alice-s-Adventures-in-Wonderland-Through-the-Looking-Glass-and-What-Alice-Found-There-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/7097090099097095/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-and-What-Alice-Found-There-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/1091094092099096094/Alice-i-Spegellandet-Alice-s-Adventures-in-Wonderland-2-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/2091095093096094/Educating-Alice-Adventures-of-a-Curious-Woman-by-Alice-Steinbach.pdf
    • http://loaminoo.linkpc.net/6092099097099/Alice-s-Adventures-in-Wonderland-Alice-s-Adventures-in-Wonderland-1-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/1090090090091096099/Horror-Hospital-Unplugged-A-Graphic-Novel-by-Dennis-Cooper.pdf
    • http://loaminoo.linkpc.net/3098095097091096/The-Cooper-Kids-The-Cooper-Kids-Adventures-1-4-by-Frank-E-Peretti.pdf
    • http://loaminoo.linkpc.net/4093099097091093/The-Adventures-of-Dennis-by-Victor-Dragunsky.pdf
    • http://loaminoo.linkpc.net/2091095093095093/The-Miss-Dennis-School-of-Writing-And-Other-Lessons-from-a-Woman-s-Life-by-Alice-Steinbach.pdf
    • http://loaminoo.linkpc.net/4094095099098092/Trapped-at-the-Bottom-of-the-Sea-The-Cooper-Kids-Adventures-4-by-Frank-E-Peretti.pdf
    • http://loaminoo.linkpc.net/1091094092097094092/Corporate-culture-and-group-values-at-Dicom-Group-plc-A-case-study-report-by-Julia-Dohrmann.pdf
    • http://loaminoo.linkpc.net/4090093096099093/The-Secret-of-the-Desert-Stone-The-Cooper-Kids-Adventures-5-by-Frank-E-Peretti.pdf
    • http://loaminoo.linkpc.net/6095092093094094/Alice-s-Adventures-in-Wonderland-And-Through-the-Looking-Glass-amp-What-Alice-Found-There-By-Lewis-Carroll-Illustrations-By-John-Tenniel-Children-s-Classics-Sir-John-Tenniel-27-July-1819---25-February-1914-Was-an-English-Illustrator-Graphic-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/2097092094094092/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/8097092091094091/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/6096092099090090/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/8094090093093/Alice-s-Adventures-in-Wonderland-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/709709009909