Malicious PDF — malware analysis report

Static analysis result for SHA-256 0407e1000380c1dd…

MALICIOUS

PDF

22.5 KB Created: 2019-05-03 07:30:51 +01:00 Authoring application: mPDF 5.7
MD5: 7ae7891706d33119f768f48926049d8c SHA-1: 7bc4329644e6caef0d1b5925989a8e1d89b9aa83 SHA-256: 0407e1000380c1dd3116c7674d7808f789ef86319934959b2b1c4e361e2bd5a3
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the dynamic DNS domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a lure to download further content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6097093097099090/Delusion-The-True-Story-of-Victorian-Superspy-Henri-Le-Caron-by-Peter-Edwards.pdf
    • http://loaminoo.linkpc.net/6097094090099091/Prince-of-Spies-Henri-Le-Caron-by-J-A-Cole.pdf
    • http://loaminoo.linkpc.net/3093094090092098/Paul-Bernardo-and-Karla-Homolka-The-True-Story-of-the-Ken-and-Barbie-Killers-Crimes-Canada-True-Crimes-That-Shocked-The-Nation-3-by-Peter-Vronsky.pdf
    • http://loaminoo.linkpc.net/1091092099095090096/Otto-the-Boy-at-the-Window-Peter-Abeles-True-Story-of-Escape-from-the-Holocaust-and-New-Life-in-America-by-Peter-Abeles.pdf
    • http://loaminoo.linkpc.net/3095098094094096/A-Dog-Called-Perth-The-True-Story-of-a-Beagle-by-Peter-Martin.pdf
    • http://loaminoo.linkpc.net/1090094099095090094/The-Escape-A-True-Story-of-Hardship-and-Adventure-by-Peter-Leupold.pdf
    • http://loaminoo.linkpc.net/2091095095094099/Unloved-The-True-Story-of-a-Stolen-Childhood-by-Peter-Roche.pdf
    • http://loaminoo.linkpc.net/1091097096099091093/Lucifer-Eve-and-Adam-the-Absolutely-True-and-Completely-Honest-Story-of-Creation-by-Peter-Wilkes.pdf
    • http://loaminoo.linkpc.net/1095094097099092/Nemesis-The-True-Story-of-Aristotle-Onassis-Jackie-O-and-the-Love-Triangle-That-Brought-Down-the-Kennedys-by-Peter-Evans.pdf
    • http://loaminoo.linkpc.net/4096095095096093/The-Bielski-Brothers-The-True-Story-of-Three-Men-Who-Defied-the-Nazis-Built-a-Village-in-the-Forest-and-Saved-1-200-Jews-by-Peter-Duffy.pdf
    • http://loaminoo.linkpc.net/4095097095097098/The-Delusion-We-All-Have-Our-Demons-The-Delusion-1-by-Laura-Gallier.pdf
    • http://loaminoo.linkpc.net/5096096097095/The-Delusion-We-All-Have-Our-Demons-The-Delusion-1-by-Laura-Gallier.pdf
    • http://loaminoo.linkpc.net/4097096092097093/Yorkshire-Ripper---The-Secret-Murders-The-True-Story-of-How-Peter-Sutcliffe-s-Terrible-Reign-of-Terror-Claimed-at-Least-Twenty-Two-More-Lives-by-Chris-Clark.pdf
    • http://loaminoo.linkpc.net/1091096097091097098/Gaslight-Villainy-True-Tales-of-Victorian-Murder-by-Grahame-Farrell.pdf
    • http://loaminoo.linkpc.net/3093094093099090/Blackmail-Sex-and-Lies-A-Victorian-True-Crime-Murder-Mystery-by-Kathryn-McMaster.pdf
    • http://loaminoo.linkpc.net/3094091092095090/The-Killing-of-Georgie-Moore-A-True-Life-Victorian-Mystery-by-Colin-Evans.pdf
    • http://loaminoo.linkpc.net/7091091092096096/Henri-Michaux-by-Peter-Broome.pdf
    • http://loaminoo.linkpc.net/7093096092098096/Peter-the-Great-by-Henri-Troyat.pdf
    • http://loaminoo.linkpc.net/9095099095098/Sparrowhawk-A-Victorian-Ghost-Story-by-Paul-Finch.pdf
    • http://loaminoo.linkpc.net/3098099091092092/The-Victorian-Christmas-Brides-Collection-9-Women-Dream-of-Perfect-Christmases-during-the-Victorian-Era-by-C-J-Chase.pdf