Malicious PDF — malware analysis report

Static analysis result for SHA-256 228625bcf95063ee…

MALICIOUS

PDF

17.6 KB Created: 2019-05-01 18:54:51 +01:00 Authoring application: mPDF 5.7
MD5: b06e40e3c16897b6a47c863f4b667111 SHA-1: 9e40be7a0530de98d5c30e52300fdb8f4d27e80d SHA-256: 228625bcf95063eed381ca7950f644f6faebdc4279148792e207113805e78324
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. It contains a large number of embedded URLs, forming a link farm. These links point to what appear to be academic papers, but the sheer volume and the nature of the heuristic firing suggest a malicious intent to drive traffic or potentially host further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/1091096096097096094/Neuro-Oncology-Part-2-Gliomas-and-Other-Primary-Tumors-of-the-Brain-and-Spinal-Cord-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/1090094094093099099/Diagnosis-and-Treatment-of-Surgical-Diseases-of-the-Spinal-Cord-and-Its-Membranes-by-Charles-Albert-Elsberg.pdf
    • http://loaminoo.linkpc.net/1091096096098098092/Vascular-Diseases-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/1091096096098099093/Neurobehavioural-Disorders-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/1091096096097098093/Extrapyramidal-Disorders-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/1091096096097096099/Systemic-Diseases-Part-I-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/6093091093096094/Hadnbook-of-Clin-Neurology-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/1091096096097095099/Handbook-of-Clinical-Neurology-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/1091096096097095091/Het-scherp-van-de-snede-de-Nederlandse-literatuur-in-meer-dan-100-polemieken-by-Pierre-Vinken.pdf
    • http://loaminoo.linkpc.net/1091096096097095090/Beer-amp-Cheese-50-Delicious-Combinations-by-Vinken-amp-Van-Tricht-by-Ben-Vinken.pdf
    • http://loaminoo.linkpc.net/5099099090096095/Treatment-Of-Degenerative-Lumbar-Spinal-Stenosis-by-Ecri.pdf
    • http://loaminoo.linkpc.net/1090095095099091094/Spinal-Disorders-Diagnosis-and-Treatment-by-Daniel-Ruge.pdf
    • http://loaminoo.linkpc.net/1091094098094094090/Manual-of-Spine-Surgery-by-Uwe-Vieweg.pdf
    • http://loaminoo.linkpc.net/4097094093094091/Gruesome-Playground-Injuries-by-Rajiv-Joseph.pdf
    • http://loaminoo.linkpc.net/2099098094097094/Once-Upon-a-Spine-A-Bibliophile-Mystery-11-by-Kate-Carlisle.pdf
    • http://loaminoo.linkpc.net/9097095092090097/Vascular-Injuries-In-Surgical-Practice-by-Frederic-S-Bongard.pdf
    • http://loaminoo.linkpc.net/7090094091093090/Athletic-Injuries-Of-The-Foot-And-Ankle-by-Annunziato-Amendola.pdf
    • http://loaminoo.linkpc.net/5093094094098093/Vaccine-Injuries-Documented-Adverse-Reactions-to-Vaccines-by-Lou-Conte.pdf
    • http://loaminoo.linkpc.net/7093099099091098/The-Spine-Basic-Evaluation-and-Mobilization-Techniques-3rd-ed-1993-by-Freddy-M-Kaltenborn.pdf
    • http://loaminoo.linkpc.net/4090092092091091/An-Eyeball-in-My-Garden-and-Other-Spine-Tingling-Poems-by-Jennifer-Cole-Judd.pdf