Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ee6a043911f7636…

MALICIOUS

PDF

15.6 KB Created: 2019-04-30 02:45:07 +01:00 Authoring application: mPDF 5.7
MD5: 0dbf9e68f3226f9206c0e72bda3a3e0a SHA-1: dfbe3435f987f082ff6fa02288b6437f8535fc4f SHA-256: 3ee6a043911f76363f0578101987ea229acea45b79c1d617076c6997aa77299c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded links. These links, primarily to PDF files hosted on 'loaminoo.linkpc.net', suggest a link farm or redirection scheme designed to lure users to potentially harmful content. The attack pattern is consistent with phishing or malware distribution via malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9778

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8094095098093097/Study-Guide-for-Siegel-and-Senna-s-Essentials-of-Criminal-Justice-by-Larry-J-Siegel.pdf
    • http://loaminoo.linkpc.net/8096099091093092/Siegel-Seelenw-chter-8-by-Kim-Richardson.pdf
    • http://loaminoo.linkpc.net/5091096097091091/Deceit-by-James-Siegel.pdf
    • http://loaminoo.linkpc.net/3090096092/Mother-Can-You-Not-by-Kate-Friedman-Siegel.pdf
    • http://loaminoo.linkpc.net/1091090093097092094/Das-zerbrochene-Siegel-by-Susanne-Eder.pdf
    • http://loaminoo.linkpc.net/1097096095094096/Invasion-of-the-Body-Snatchers-by-Don-Siegel.pdf
    • http://loaminoo.linkpc.net/1091091093092093097/The-Terrorist-Next-Door-by-Sheldon-Siegel.pdf
    • http://loaminoo.linkpc.net/6096090092099093/Love-s-Riff-by-Jenny-Siegel.pdf
    • http://loaminoo.linkpc.net/2094090095095090/Pride-and-Prejudice-by-Fern-Siegel.pdf
    • http://loaminoo.linkpc.net/3090096098090093/Alpha-Centauri-by-Robert-Siegel.pdf
    • http://loaminoo.linkpc.net/1090093099098098097/Violence-Risk-amp-Threat-Assessment-A-Practical-Guide-for-Mental-Health-amp-Criminal-Justice-Professionals-by-J-Reid-Meloy.pdf
    • http://loaminoo.linkpc.net/1091092091090093098/The-Cobalt-Prince-5-Worlds-2-by-Mark-Siegel.pdf
    • http://loaminoo.linkpc.net/8096099092098096/Das-Siegel-des-Olymps-Im-Bann-des-Schicksals-by-Romana-R-K-.pdf
    • http://loaminoo.linkpc.net/1091092090099097093/Brainstorm-The-Teenage-Brain-from-the-Inside-Out-by-Daniel-J-Siegel.pdf
    • http://loaminoo.linkpc.net/2099092096090095/Nonparametric-Statistics-For-The-Behavioral-Sciences-by-Sidney-Siegel.pdf
    • http://loaminoo.linkpc.net/1091092091090093093/Lois-Lane-A-Celebration-of-75-Years-by-Jerry-Siegel.pdf
    • http://loaminoo.linkpc.net/6095091095093095/Information-System-Management-Handbook-by-Joel-G-Siegel.pdf
    • http://loaminoo.linkpc.net/1091092091090090097/The-Restless-Dead-of-Siegel-City-by-Blake-M-Petit.pdf
    • http://loaminoo.linkpc.net/6095091095094090/International-Encyclopedia-of-Technical-Analysis-by-Joel-G-Siegel.pdf
    • http://loaminoo.linkpc.net/9096095090099095/Lillian-Wald-of-Henry-Street-by-Beatrice-Siegel.pdf
    • http://loaminoo.linkpc.net/1090093099098098097/Violence-Risk-amp-Threat-Assessment-A-Practical-Guide-for-Mental