Malicious PDF — malware analysis report

Static analysis result for SHA-256 25b6187138176be5…

MALICIOUS

PDF

19.0 KB Created: 2019-05-02 00:42:41 +01:00 Authoring application: mPDF 5.7
MD5: 243422c1ddc0dc59770875b745359880 SHA-1: f34e9b173b857666767c5e65685e4ddae9c014f1 SHA-256: 25b6187138176be5a7b1b1b57c3f8a70ea2ca13c102a839d83533cf3d645272f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to book-related PDFs hosted on the domain loaminoo.linkpc.net. This suggests a link-farming or redirection scheme designed to lure users to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3094095099096090/Soul-of-the-World-The-Ascension-Cycle-1-by-David-Mealing.pdf
    • http://loaminoo.linkpc.net/1093094095096094/Brink-of-Eternity-Guardians-of-Ascension-2-5-Dawn-of-Ascension-1-by-Caris-Roane.pdf
    • http://loaminoo.linkpc.net/7099095099093097/Eclipse-The-Lost-Book-of-Ascension-Books-of-Ascension-3-by-Dirk-Strasser.pdf
    • http://loaminoo.linkpc.net/5091092097094/Ascension-An-Analysis-of-the-Art-of-Ascension-as-Taught-by-the-Ishayas-by-Maharishi-Sadasiva-Isham.pdf
    • http://loaminoo.linkpc.net/1093094096093099/The-Darkening-Guardians-of-Ascension-6-5-Dawn-of-Ascension-2-by-Caris-Roane.pdf
    • http://loaminoo.linkpc.net/2094093094094091/Ascension-The-Revelation-Ascension-Trilogy-1-by-Jennifer-Turner.pdf
    • http://loaminoo.linkpc.net/2092098091091090/Soul-Whispers-Collective-Wisdom-from-Soul-Coaches-around-the-World-by-Sophia-Fairchild.pdf
    • http://loaminoo.linkpc.net/1096097092094093/The-Ascension-Mysteries-Revealing-the-Cosmic-Battle-Between-Good-and-Evil-by-David-Wilcock.pdf
    • http://loaminoo.linkpc.net/1095098092093092/Lord-of-Lies-The-Ea-Cycle-3-by-David-Zindell.pdf
    • http://loaminoo.linkpc.net/2095099099092092/The-System-of-the-World-The-Baroque-Cycle-3-by-Neal-Stephenson.pdf
    • http://loaminoo.linkpc.net/1096094094098099/World-s-End-The-Snow-Queen-Cycle-2-by-Joan-D-Vinge.pdf
    • http://loaminoo.linkpc.net/2091096090098098/This-Is-My-Letter-To-The-World-The-Omikuji-Project-Cycle-One-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/1090094095096094/The-Cycle-of-Cosmic-Catastrophes-How-a-Stone-Age-Comet-Changed-the-Course-of-World-Culture-by-Richard-Firestone.pdf
    • http://loaminoo.linkpc.net/9090099093094/Year-of-the-Unicorn-Witch-World-Series-2-High-Hallack-Cycle-1-by-Andre-Norton.pdf
    • http://loaminoo.linkpc.net/1090090095093092091/Horn-Crown-Witch-World-Series-2-High-Hallack-Cycle-0-by-Andre-Norton.pdf
    • http://loaminoo.linkpc.net/2097094099090096/The-Crystal-Gryphon-Witch-World-Series-2-High-Hallack-Cycle-5-by-Andre-Norton.pdf
    • http://loaminoo.linkpc.net/2092097097095096/Cycle-of-Rice-Cycle-of-Life-A-Story-of-Sustainable-Farming-by-Jan-Reynolds.pdf
    • http://loaminoo.linkpc.net/5091096097093092/Birth-Marriage-and-Death-Ritual-Religion-and-the-Life-Cycle-in-Tudor-and-Stuart-England-by-David-Cressy.pdf
    • http://loaminoo.linkpc.net/3096096098092096/The-Soul-of-the-World-by-Roger-Scruton.pdf
    • http://loaminoo.linkpc.net/9098096096097092/Apprenticeship-of-the-Soul-by-David-Christopher-McCombs.pdf
    • http://loaminoo.linkpc.net/1096097092094093/The-Ascension-Mysteries-Revealin