Malicious PDF — malware analysis report

Static analysis result for SHA-256 05803124a3f25bb2…

MALICIOUS

PDF

17.7 KB Created: 2019-05-01 18:02:59 +01:00 Authoring application: mPDF 5.7
MD5: ed7b6b162696849bbef81e4d34e902af SHA-1: 40ba5a714fe566fac056cfe0cfe17893f5a2535e SHA-256: 05803124a3f25bb216649bba1aa0ea20eb659b0a2797757a28962e1e4a637a7e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, many of which are hosted on the dynamic DNS domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8094093091098090/Federal-Electoral-Districts-Representation-Order-of-1996-Circonscriptions-Electorales-Federales-Decret-de-Representation-Electorale-de-1996-by-Elections-Canada.pdf
    • http://loaminoo.linkpc.net/8094093091099094/Federal-Electoral-Districts-Representation-Order-of-1996-Circonscriptions-Electorales-Federales-Decret-de-Representation-Electorale-de-1996-by-Elections-Canada.pdf
    • http://loaminoo.linkpc.net/5097094093094094/Parties-and-Elections-in-America-The-Electoral-Process-by-L-Maisel.pdf
    • http://loaminoo.linkpc.net/6099097092099095/Elections-Electoral-Systems-and-Volatil-by-Gianfranco-Baldini.pdf
    • http://loaminoo.linkpc.net/8095094099093/The-World-as-Will-and-Representation-Vol-2-by-Arthur-Schopenhauer.pdf
    • http://loaminoo.linkpc.net/5097094093095099/Parties-and-Elections-in-America-The-Electoral-Process-by-Mark-D-Brewer.pdf
    • http://loaminoo.linkpc.net/9097092095091098/Thor-1966-1996-456-by-Tom-DeFalco.pdf
    • http://loaminoo.linkpc.net/1091091094094092092/Thor-1966-1996-453-by-Tom-DeFalco.pdf
    • http://loaminoo.linkpc.net/8091095095092092/Bridport-Prize-1996-Sb-by-Mise.pdf
    • http://loaminoo.linkpc.net/1090096092095091099/Thor-1966-1996-454-by-Tom-DeFalco.pdf
    • http://loaminoo.linkpc.net/1090098095096094098/Difference-On-Representation-amp-Sexuality-by-Peter-Wollen.pdf
    • http://loaminoo.linkpc.net/5091098090092091/Sectionalism-And-Representation-In-South-Carolina-by-W-A-Schaper.pdf
    • http://loaminoo.linkpc.net/4096096099094/The-World-as-Will-and-Representation-Volume-1-by-Arthur-Schopenhauer.pdf
    • http://loaminoo.linkpc.net/1091098099096091096/Best-Lesbian-Erotica-1996-by-Tristan-Taormino.pdf
    • http://loaminoo.linkpc.net/6096091092093090/Je-Francois-Mitterrand-1981-1996-by-Wiaz.pdf
    • http://loaminoo.linkpc.net/1091096096099091091/Avengers-1963-1996-377-by-Joey-Cavalieri.pdf
    • http://loaminoo.linkpc.net/5099099090097095/Healthcare-Standards-Directory-1996-by-Ecri.pdf
    • http://loaminoo.linkpc.net/4091095096091094/Looking-beyond-the-frame-racism-representation-amp-resistance-by-Michelle-Reeves.pdf
    • http://loaminoo.linkpc.net/9092092091094091/The-Roles-Of-Representation-In-School-Mathematics-by-Albert-A-Cuoco.pdf
    • http://loaminoo.linkpc.net/5092097098093097/Art-and-Illusion-A-Study-in-the-Psychology-of-Pictorial-Representation-by-E-H-Gombrich.pdf