Malicious PDF — malware analysis report

Static analysis result for SHA-256 4445b181879f0e41…

MALICIOUS

PDF

20.1 KB Created: 2019-05-03 12:48:38 +01:00 Authoring application: mPDF 5.7
MD5: f6caa527f2ced099f4eb95ff52c99764 SHA-1: d243144e0458d58c4b3dbbdb6f9edfa9f52e8b84 SHA-256: 4445b181879f0e416db5915816127158ee745763502285041b7a3d08d07e84c9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: User Execution

The PDF was flagged by a critical heuristic for containing a large number of external links, indicating a link farm. The ML classifier also strongly indicated maliciousness. While no scripts were extracted, the presence of numerous links suggests a phishing or redirection attempt to malicious content hosted on the 'loaminoo.linkpc.net' domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.link
    • http://loaminoo.linkpc.net/1090093090098095094/SOFSEM-2004-Theory-and-Practice-of-Computer-Science-30th-Conference-on-Current-Trends-in-Theory-and-Practice-of-Computer-Science-Merin-Czech-Republic-2004-Lecture-Notes-in-Computer-Science-by-Peter-Van-Emde-Boas.pdf
    • http://loaminoo.linkpc.net/8090091098092090/Theory-and-Practice-of-Managed-Competition-in-Health-Care-Finance-Lectures-in-Economics-Theory-Institutions-Policy-by-Alain-C-Enthoven.pdf
    • http://loaminoo.linkpc.net/4097090091099095/Applications-Of-Feminist-Legal-Theory-by-D-Kelly-Weisberg.pdf
    • http://loaminoo.linkpc.net/4094091099099097/Politics-of-Reality-Essays-in-Feminist-Theory-by-Marilyn-Frye.pdf
    • http://loaminoo.linkpc.net/5090097098092097/The-Subject-of-Liberty-Toward-a-Feminist-Theory-of-Freedom-by-Nancy-J-Hirschmann.pdf
    • http://loaminoo.linkpc.net/7095093099098099/Figures-of-Resistance-Essays-in-Feminist-Theory-by-Teresa-de-Lauretis.pdf
    • http://loaminoo.linkpc.net/8093097093090092/Harmony-Its-No-and-Practice-Its-Theory-Ts-Theory-by-Ebenezer-Prout-B-Prout.pdf
    • http://loaminoo.linkpc.net/2097094094096098/The-Sexual-Politics-of-Meat-A-Feminist-Vegetarian-Critical-Theory-by-Carol-J-Adams.pdf
    • http://loaminoo.linkpc.net/1090090096095096098/Theory-amp-Practice-in-Listening-by-Dunkel.pdf
    • http://loaminoo.linkpc.net/9094090092093/Theory-and-practice-of-hell-by-Eugen-Kogon.pdf
    • http://loaminoo.linkpc.net/9098090090091094/Theory-and-Practice-of-Seamanship-XI-by-Graham-Danton.pdf
    • http://loaminoo.linkpc.net/8095090094098097/The-Theory-and-Practice-of-Socialism-by-John-Strachey.pdf
    • http://loaminoo.linkpc.net/5096098091092093/The-Practice-and-Theory-of-Bolshevism-by-Bertrand-Russell.pdf
    • http://loaminoo.linkpc.net/3091098096091097/Magick-in-Theory-and-Practice-by-Aleister-Crowley.pdf
    • http://loaminoo.linkpc.net/2090099094092091/Abortion-And-Woman-s-Choice-The-State-Sexuality-and-Reproductive-Freedom-Northeastern-Series-on-Feminist-Theory-by-Rosalind-Pollack-Petchesky.pdf
    • http://loaminoo.linkpc.net/7096096099095097/Network-Coding-From-Theory-to-Practice-by-Muriel-Medard.pdf
    • http://loaminoo.linkpc.net/1091098097092099094/Central-Banking-in-Theory-and-Practice-by-Alan-S-Blinder.pdf
    • http://loaminoo.linkpc.net/1091095099095094097/Psychodynamic-Psychiatry-Theory-amp-Practice-1-by-John-Frosch.pdf
    • http://loaminoo.linkpc.net/1090094090094095098/Random-Vibrations-Theory-and-Practice-by-Paul-H-Wirsching.pdf
    • http://loaminoo.linkpc.net/8094096090093098/Theory-and-Practice-of-the-Philosopher-s-Stone-by-Nicholas-Flamel.pdf