Malicious PDF — malware analysis report

Static analysis result for SHA-256 5a92dff64e3ba6ad…

MALICIOUS

PDF

18.6 KB Created: 2019-04-30 02:25:35 +01:00 Authoring application: mPDF 5.7
MD5: 4c844144242a52793fa305d9607dfdbb SHA-1: 6c9e3e461e5756fe81e1be606735a37ff674bb71 SHA-256: 5a92dff64e3ba6ada19a40c2db9f850b5052c082e232f9cb46a9336547fa59b9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs, forming a link farm. These URLs point to various PDF files hosted on the dynamic DNS domain 'loaminoo.linkpc.net'. The primary purpose appears to be directing users to these external resources, likely as a form of SEO spam or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091095097090092096/Wie-ich-lernte-dich-zu-hassen-Wie-ich-lernte-1-by-Vanessa-Clark.pdf
    • http://loaminoo.linkpc.net/5094097090099090/Der-Tag-an-dem-ich-zaubern-lernte-by-Natalie-Lloyd.pdf
    • http://loaminoo.linkpc.net/1090094097098098096/Der-Sommer-in-dem-Linda-schwimmen-lernte-by-Roy-Jacobsen.pdf
    • http://loaminoo.linkpc.net/1091095097090093095/Als-das-Nashorn-fliegen-lernte-by-Nadia-Adina-Rose.pdf
    • http://loaminoo.linkpc.net/1091095097090096095/Irgendwohin-oder-der-Tag-an-dem-George-das-Fliegen-lernte-by-Gus-Gordon.pdf
    • http://loaminoo.linkpc.net/1091095097092092094/Depressionen-wie-ich-lernte-meine-Seele-auszutricksen-by-Maria-Berger.pdf
    • http://loaminoo.linkpc.net/1091095097092093091/Verschl-sselt---Wie-ich-sichere-Kommunikation-im-Netz-lernte-by-Tobias-Gillen.pdf
    • http://loaminoo.linkpc.net/7096094097098092/How-to-be-a-woman-Wie-ich-lernte-eine-Frau-zu-sein-by-Caitlin-Moran.pdf
    • http://loaminoo.linkpc.net/8099090090098095/The-Art-of-Asking-Wie-ich-aufh-rte-mir-Sorgen-zu-machen-und-lernte-mir-helfen-zu-lassen-by-Amanda-Palmer.pdf
    • http://loaminoo.linkpc.net/1091095097092093095/Kalte-K-chewie-Ich-In-Der-Antarktis-Nicht-Nur-Das-Kochen-Lernte-by-Alexa-Thomson.pdf
    • http://loaminoo.linkpc.net/9098091095094098/Tour-d-amour-Wie-ich-lernte-Fr-sche-und-Franzosen-zu-lieben-by-Elizabeth-Bard.pdf
    • http://loaminoo.linkpc.net/1091095097090093090/Mit-dem-Piano-in-die-Pyren-en-Wie-ich-lernte-unter-lauter-Franzosen-zu-leben-by-Tony-Hawks.pdf
    • http://loaminoo.linkpc.net/8099096097095092/Die-Primaten-von-der-Park-Avenue-M-tter-auf-High-Heels-und-was-ich-unter-ihnen-lernte-by-Wednesday-Martin.pdf
    • http://loaminoo.linkpc.net/9092098099090092/Ich-brauche-dich-mehr-als-ich-dich-liebe-und-ich-liebe-dich-so-sehr-by-Gunnar-Ardelius.pdf
    • http://loaminoo.linkpc.net/1090091093091093099/Liebte-ich-Dich-bevor-ich-Dich-traf-by-Marion-Gallis.pdf
    • http://loaminoo.linkpc.net/1090094091090094097/Der-Junge-der-nicht-hassen-wollte-by-Shlomo-Graber.pdf
    • http://loaminoo.linkpc.net/2092094097097090/Father-Son-and-Constitution-How-Justice-Tom-Clark-and-Attorney-General-Ramsey-Clark-Shaped-American-Democracy-by-Alexander-Wohl.pdf
    • http://loaminoo.linkpc.net/6098091099091095/The-Classic-Clark-Collection-by-Mary-Higgins-Clark.pdf
    • http://loaminoo.linkpc.net/9090091099093095/PHOENIX-Durch-dich-erwacht-PHOENIX---durch-dich-erwacht-1-by-Saraphina-J-C-Rose.pdf
    • http://loaminoo.linkpc.net/8093098092091091/Clark-The-Autobiography-of-Clark-Terry-by-Clark-Terry.pdf