Malicious PDF — malware analysis report

Static analysis result for SHA-256 53ac073ac2a5618d…

MALICIOUS

PDF

16.4 KB Created: 2019-05-01 19:51:14 +01:00 Authoring application: mPDF 5.7
MD5: 29c18a9a2327b578ec24a18158cf82b4 SHA-1: 2910b267723bf8740cc4e42fdfeb2606d5222cc2 SHA-256: 53ac073ac2a5618d751137621b8014d2c0c691a18447d0f0da3448728b4ae26e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO spam or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a link farm hosted on the loaminoo.linkpc.net domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1095097093094094/Ryekk-Terris-Trilogy-3-by-Timothy-James.pdf
    • http://loaminoo.linkpc.net/1095096096097093/Jack-Terris-Trilogy-1-by-Timothy-James.pdf
    • http://loaminoo.linkpc.net/1095097094096091/The-Evil-at-the-Back-of-the-Cave-The-Oen-Trilogy-2-by-Timothy-James.pdf
    • http://loaminoo.linkpc.net/4091090098097092/Someone-Like-You-by-Timothy-James-Beck.pdf
    • http://loaminoo.linkpc.net/4091091090090092/It-Had-to-Be-You-Manhattan-1-by-Timothy-James-Beck.pdf
    • http://loaminoo.linkpc.net/5094097093092090/James-in-the-House-of-Aunt-Prudence-by-Timothy-Bush.pdf
    • http://loaminoo.linkpc.net/2096098098092/Somebody-Else-s-Child-by-Terris-McMahan-Grimes.pdf
    • http://loaminoo.linkpc.net/2094097096093096/Tucker-And-The-Horse-Thief-by-Susan-Terris.pdf
    • http://loaminoo.linkpc.net/3092094094093093/The-Thrawn-Omnibus-Star-Wars-The-Thrawn-Trilogy-1-3-by-Timothy-Zahn.pdf
    • http://loaminoo.linkpc.net/1090094090097093090/Legenden-om-Star-Wars-Imperiets-Arvinge-Star-Wars-The-Thrawn-Trilogy-1-by-Timothy-Zahn.pdf
    • http://loaminoo.linkpc.net/8092090099096090/Digital-Voodoo-The-Collected-Works-of-Timothy-O-Goyette-by-Timothy-O-Goyette.pdf
    • http://loaminoo.linkpc.net/1090093099099092/In-His-Image-The-Christ-Clone-Trilogy-1-by-James-BeauSeigneur.pdf
    • http://loaminoo.linkpc.net/4095090091094099/Birth-Of-An-Age-The-Christ-Clone-Trilogy-2-by-James-BeauSeigneur.pdf
    • http://loaminoo.linkpc.net/3090093099091096/The-Shadow-of-What-Was-Lost-The-Licanius-Trilogy-1-by-James-Islington.pdf
    • http://loaminoo.linkpc.net/6096094093090091/Gaia-s-Demise-The-Baronies-Trilogy-2-Deathlands-47-by-James-Axler.pdf
    • http://loaminoo.linkpc.net/4091096091097093/Counterfeit-Lady-James-River-Trilogy-1-by-Jude-Deveraux.pdf
    • http://loaminoo.linkpc.net/4090092094098096/The-Cross-and-the-Trinity-The-James-Lucas-Trilogy-2-by-Elizabeth-Lister.pdf
    • http://loaminoo.linkpc.net/4090092099095095/A-Numinous-Light-The-James-Lucas-Trilogy-3-by-Elizabeth-Lister.pdf
    • http://loaminoo.linkpc.net/7091090095095091/American-Tabloid-and-The-Cold-Six-Thousand-Underworld-U-S-A-Trilogy-Vol-1-by-James-Ellroy.pdf
    • http://loaminoo.linkpc.net/5097093094095/The-Rise-of-Darth-Vader-Star-Wars-The-Dark-Lord-Trilogy-3-by-James-Luceno.pdf