Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a58d941b77476e6…

MALICIOUS

PDF

17.8 KB Created: 2019-04-30 00:00:51 +01:00 Authoring application: mPDF 5.7
MD5: 1339e77360caf6283ff2b7476113c4c4 SHA-1: fb7c8baadc797350329a89c2932b03dd2a4ed62a SHA-256: 0a58d941b77476e62034bac0e2cd451819651234c9cd569eb0ebe8532a35e3fd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links to external PDF files hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or SEO poisoning attack, designed to drive traffic to malicious or low-quality content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7095093092099096/Valuing-the-Environment-Six-Case-Studies-by-Jean-Philippe-Barde.pdf
    • http://loaminoo.linkpc.net/7095093092098099/Arming-the-South-by-Jean-Philippe-Barde.pdf
    • http://loaminoo.linkpc.net/1091090091098098093/Military-Intervenes-The-Case-Studies-in-Political-Development-Case-Studies-in-Political-Development-by-Henry-Bienen.pdf
    • http://loaminoo.linkpc.net/5094094095095091/Aesthetik-Des-Fragments-Fragmentarisches-Erzaehlen-Bei-Jean-Philippe-Toussaint-Und-Jean-Echenoz-by-Christine-Keidel.pdf
    • http://loaminoo.linkpc.net/1091092090099092092/On-Liberty-A-Translation-into-Modern-English-ISR-Business-amp-the-political-legal-environment-studies-Book-6-by-John-Stuart-Mill.pdf
    • http://loaminoo.linkpc.net/6095097099090095/Case-Studies-Art-in-a-Valise-by-Katonah-Museum-of-Art.pdf
    • http://loaminoo.linkpc.net/5092099096095092/Moi-Jean-Cocteau-by-Philippe-de-Miomandre.pdf
    • http://loaminoo.linkpc.net/2093097092/The-6-41-to-Paris-by-Jean-Philippe-Blondel.pdf
    • http://loaminoo.linkpc.net/7096094099099/Camera-by-Jean-Philippe-Toussaint.pdf
    • http://loaminoo.linkpc.net/1091095096091093097/The-Biology-of-Consciousness-Case-Studies-in-Kundalini-by-J-J-Semple.pdf
    • http://loaminoo.linkpc.net/8092094094096090/Case-Studies-in-Ethics-and-HIV-Research-by-Sana-Loue.pdf
    • http://loaminoo.linkpc.net/8097094091098094/Case-Studies-In-Environmental-Science-by-Robert-M-Schoch.pdf
    • http://loaminoo.linkpc.net/6090091096098098/Making-Love-by-Jean-Philippe-Toussaint.pdf
    • http://loaminoo.linkpc.net/1090094093091093098/Case-Studies-in-Immunology-Fifth-Edition-Factor-I-Deficiency-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/1090094093091094096/Case-Studies-in-Immunology-Fifth-Edition-Congenital-Asplenia-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/1090094093092090097/Case-Studies-in-Immunology-Fifth-Edition-Multiple-Myeloma-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/1090094093090093095/Case-Studies-in-Immunology-Fifth-Edition-Mhc-Class-II-Deficiency-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/1090094093092090093/Case-Studies-in-Immunology-Fifth-Edition-Myasthenia-Gravis-by-Raif-Geha.pdf
    • http://loaminoo.linkpc.net/6094093096095/Journey-of-Souls-Case-Studies-of-Life-Between-Lives-by-Michael-Newton.pdf
    • http://loaminoo.linkpc.net/6097097098092097/R-veil-ultra-matinal-by-Jean-Philippe-Touzeau.pdf