Malicious PDF — malware analysis report

Static analysis result for SHA-256 444d698253dbdff5…

MALICIOUS

PDF

13.9 KB Created: 2019-05-04 14:00:08 +01:00 Authoring application: mPDF 5.7
MD5: eaafa344e9a95f6f10c2f38200716225 SHA-1: 478a5f7b25a84998cc557fb8b5ed4f013cb7bce1 SHA-256: 444d698253dbdff5c465829cf81c0601085751ea09d99c8099761bb9273312b7
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1204.002 Malicious File:Malicious PDF

The PDF file was flagged by a machine learning classifier as malicious and contains a large number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates that these links point to numerous PDF documents hosted on the 'loaminoo.linkpc.net' domain. This suggests a tactic to manipulate search engine results or to distribute further malicious content disguised as academic papers. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8099099097091092/Keats-and-Hellenism-An-Essay-by-Martin-Aske.pdf
    • http://loaminoo.linkpc.net/8099099098095098/Hellenism-and-the-Postcolonialist-Imagination-Yeats-Cavafy-Walcott-by-Martin-McKinsey.pdf
    • http://loaminoo.linkpc.net/8099099096099098/The-Art-of-Greece-the-Age-of-Hellenism-by-T-B-L-Webster.pdf
    • http://loaminoo.linkpc.net/8099099097095097/Hellenism-and-Christianity-by-W-Malley.pdf
    • http://loaminoo.linkpc.net/8099099096096098/The-Heritage-Of-Hellenism-by-John-Ferguson.pdf
    • http://loaminoo.linkpc.net/8099099096096092/Hellenism-by-Norman-DeMattos-Bentwich.pdf
    • http://loaminoo.linkpc.net/8099099096099094/Hellenism-and-Christianity-by-Edwyn-Bevan.pdf
    • http://loaminoo.linkpc.net/8099099097095098/Hellenism-and-Hebraism-by-Borys-Kowalsky.pdf
    • http://loaminoo.linkpc.net/4097090095095090/John-Keats-by-John-Keats.pdf
    • http://loaminoo.linkpc.net/8099099097095093/Classical-Anatolia-The-Glory-of-Hellenism-by-Harry-Brewster.pdf
    • http://loaminoo.linkpc.net/8099099098091093/Wound-of-Greece-Studies-in-Neo-Hellenism-by-Philip-Sherrard.pdf
    • http://loaminoo.linkpc.net/1098092096099095/Ode-to-a-Nightingale-by-John-Keats.pdf
    • http://loaminoo.linkpc.net/8099099096096095/Heritage-and-Hellenism-The-Reinvention-of-Jewish-Tradition-by-Erich-S-Gruen.pdf
    • http://loaminoo.linkpc.net/6092093090094094/Regards-to-the-Man-in-the-Moon-by-Ezra-Jack-Keats.pdf
    • http://loaminoo.linkpc.net/4093098097090091/See-Europe-Next-Time-You-Go-There-by-John-C-Keats.pdf
    • http://loaminoo.linkpc.net/3098092099094/The-Complete-Poems-by-John-Keats.pdf
    • http://loaminoo.linkpc.net/3098091096097096/The-Trip-by-Ezra-Jack-Keats.pdf
    • http://loaminoo.linkpc.net/5091090096098098/John-Keats-by-Robert-Gittings.pdf
    • http://loaminoo.linkpc.net/1091096093094099097/Endymion-and-Other-Poems-by-John-Keats.pdf
    • http://loaminoo.linkpc.net/1090096099090094094/Keats-Leopardi-amp-Holderlin-by-Ray-Fleming.pdf
    • http://loaminoo.linkpc.net/8099099098091093/W