Malicious PDF — malware analysis report

Static analysis result for SHA-256 1208c0c1f05fe3fe…

MALICIOUS

PDF

21.0 KB Created: 2019-05-02 17:25:10 +01:00 Authoring application: mPDF 5.7
MD5: 26758e4c1004ed06a91bf5bc17b5ed9f SHA-1: 0a3c891a24cf2fdba0a99bb0660091dc9e816ded SHA-256: 1208c0c1f05fe3fe62973be89a80f4a3dcc01f9ccabe5d4edfa0ae4e89e845bb
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the dynamic DNS domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a mechanism to distribute further malicious content. The ML classifier also flagged this PDF as malicious, supporting the suspicious nature of the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8091091090096092/Naruto-Vol-01-The-Tests-of-the-Ninja-Collector-s-edition-Includes-2006-Naruto-Calendar-by-Masashi-Kishimoto.pdf
    • http://loaminoo.linkpc.net/6098090096097098/Fragrances-of-the-World-2006-Parfums-Du-Monde-2006-by-Michael-Edwards.pdf
    • http://loaminoo.linkpc.net/1091092096098091090/Icsp-06-2006-8th-International-Conference-on-Signal-Processing-Proceedings-November-16-20-2006-Guilin-China-by-Beijing-Jiao-Tong-Da-Xue.pdf
    • http://loaminoo.linkpc.net/1091092096099096093/Isape-06-2006-7th-International-Symposium-on-Antennas-Propagation-and-Em-Theory-Proceedings-Oct-26-29-2006-Guilin-China-by-Institute-of-Electrical-and-Electronics-Engineers.pdf
    • http://loaminoo.linkpc.net/1091092096098090096/Knowledge-Science-Engineering-and-Management-First-International-Conference-KSEM-2006-Guilin-China-August-5-8-2006-Proceedings-by-Jerome-Lang.pdf
    • http://loaminoo.linkpc.net/7091096095092097/Artificial-Intelligence-and-Soft-Computing---Icaisc-2006-8th-International-Conference-Zakopane-Poland-June-25-29-2006-Proceedings-by-Leszek-Rutkowski.pdf
    • http://loaminoo.linkpc.net/6091098099096090/Calendar-Girl-November-Calendar-Girl-Buch-11-by-Audrey-Carlan.pdf
    • http://loaminoo.linkpc.net/1090099091098092097/Database-and-XML-Technologies-4th-International-XML-Database-Symposium-Xsym-2006-Seoul-Korea-September-10-11-2006-Proceedings-by-Sihem-Amer-Yahia.pdf
    • http://loaminoo.linkpc.net/6091098099096099/Calendar-Girl-September-Calendar-Girl-9-by-Audrey-Carlan.pdf
    • http://loaminoo.linkpc.net/4099098095096094/Are-You-Together-by-frogs-of-war.pdf
    • http://loaminoo.linkpc.net/4097091096091/Frogs-by-Aristophanes.pdf
    • http://loaminoo.linkpc.net/7099092094099/The-Way-Of-A-Man-by-Frans-Eemil-Sillanp-.pdf
    • http://loaminoo.linkpc.net/1096097093090090/Too-Many-Frogs-by-Sandy-Asher.pdf
    • http://loaminoo.linkpc.net/1098094090096092/Passionate-Journey-by-Frans-Masereel.pdf
    • http://loaminoo.linkpc.net/2095090090093097/The-Long-Ships-by-Frans-G-Bengtsson.pdf
    • http://loaminoo.linkpc.net/3092097098095098/De-kip-die-over-de-soep-vloog-by-Frans-Pointl.pdf
    • http://loaminoo.linkpc.net/2099097099093099/Dibdin-in-Paris-by-Frans-A-Janssen.pdf
    • http://loaminoo.linkpc.net/9098096093093094/Concordant-Reference-by-Frans-Vermeulen.pdf
    • http://loaminoo.linkpc.net/7091092093097099/The-Frogs-and-Their-Monster-by-Swami-Chidvilasananda.pdf
    • http://loaminoo.linkpc.net/1095096097092091/To-Sing-Frogs-by-John-M-Simmons.pdf