Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a8273ae355be6e9…

MALICIOUS

PDF

21.8 KB Created: 2019-05-03 07:35:25 +01:00 Authoring application: mPDF 5.7
MD5: 0f5c455d2ead253c4d412ca6c65cce3f SHA-1: 27b1b89bdbdb4a73bde298d488d6d493e8258050 SHA-256: 4a8273ae355be6e94e4280e8e05e80135695e48369dab5ac4832161d4b15825b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS heuristic also flagged this file with high confidence. The embedded URLs, while many are marked as benign, all point to the same suspicious domain 'loaminoo.linkpc.net', suggesting a coordinated effort to distribute content or potentially malicious payloads through these links. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6093096093090098/The-Iliad-by-Homer-Rendered-Into-English-Prose-by-Samuel-Butler-by-Samuel-Butler.pdf
    • http://loaminoo.linkpc.net/4097091095098/The-Way-of-All-Flesh-by-Samuel-Butler.pdf
    • http://loaminoo.linkpc.net/8090095093099098/The-Way-of-All-Flesh-by-Samuel-Butler.pdf
    • http://loaminoo.linkpc.net/2095095092090098/Erewhons-Of-The-Eye-Samuel-Butler-As-Painter-Photographer-amp-Art-Critic-by-E-S-Shaffer.pdf
    • http://loaminoo.linkpc.net/5090092095095096/The-Grove-Centenary-Editions-of-Samuel-Beckett-Boxed-Set-Contains-Novels-I-and-II-of-Samuel-Beckett-The-Dramatic-Works-of-Samuel-Beckett-and-The-Poems-Short-Fiction-and-Critcism-of-Samuel-Beckett-by-Samuel-Beckett.pdf
    • http://loaminoo.linkpc.net/7097095099096097/Ancient-Classics-for-English-Readers-Homer-The-Iliad-by-Homer.pdf
    • http://loaminoo.linkpc.net/5095094094091090/The-Iliad-of-Homer-In-English-Hexameter-Verse-by-Homer.pdf
    • http://loaminoo.linkpc.net/3093091094099093/The-Complete-Short-Prose-1929-1989-by-Samuel-Beckett.pdf
    • http://loaminoo.linkpc.net/9092092094094098/The-Poetry-of-Homer-Edited-with-an-Introduction-by-Bruce-Heiden-by-Samuel-Eliot-Bassett.pdf
    • http://loaminoo.linkpc.net/7096094098092099/Expositions-of-Holy-Scripture-Deuteronomy-Joshua-Judges-Ruth-and-First-Book-of-Samuel-Second-Samuel-First-Kings-and-Second-Kings-chapters-I-to-VII-by-Alexander-MacLaren.pdf
    • http://loaminoo.linkpc.net/2095092096099098/A-War-Imagined-The-First-World-War-and-English-Culture-by-Samuel-Hynes.pdf
    • http://loaminoo.linkpc.net/9092092093090098/Homer-the-Iliad-Or-Achilles-Wrath-at-the-Siege-of-Ilion-1864-by-Homer.pdf
    • http://loaminoo.linkpc.net/1090095096097093093/The-Iliad-of-Homer-Annotated-Literary-Classics-Collection-by-Homer.pdf
    • http://loaminoo.linkpc.net/7091093092092098/The-Iliad-of-Homer-Active-TOC-Free-Audiobook-A-to-Z-Classics-by-Homer.pdf
    • http://loaminoo.linkpc.net/6094097090091091/The-Iliad-of-Homer-with-Additional-Notes-Critical-and-Illustrative-by-Homer.pdf
    • http://loaminoo.linkpc.net/7099098092096/Novels-II-of-Samuel-Beckett-Volume-II-of-The-Grove-Centenary-Editions-by-Samuel-Beckett.pdf
    • http://loaminoo.linkpc.net/5099097098091091/Diary-of-Samuel-Pepys---Volume-26-January-February-1663-64-by-Samuel-Pepys.pdf
    • http://loaminoo.linkpc.net/1094093090097092/A-Journey-to-the-Northern-Ocean-The-Adventures-of-Samuel-Hearne-by-Samuel-Hearne.pdf
    • http://loaminoo.linkpc.net/8094099097094099/One-Hundred-Saints-Their-Lives-and-Likenesses-Drawn-from-Butler-s-Lives-of-the-Saints-and-Great-Works-of-Western-Art-by-Alban-Butler.pdf
    • http://loaminoo.linkpc.net/4090097097090090/The-Professor-and-the-English-Spy-Memoir-of-a-World-War-II-French-Italian-Underground-Journey-1942-1944-by-Samuel-Berlin.pdf
    • http://loaminoo.linkpc.net/309309109409909