Malicious PDF — malware analysis report

Static analysis result for SHA-256 5cab3671c78f857e…

MALICIOUS

PDF

21.1 KB Created: 2019-04-30 17:27:12 +01:00 Authoring application: mPDF 5.7
MD5: 2efff2e699a4996b05f299d74ce139df SHA-1: e39b4cb2d76d29fe1ffc3f05e71f4e48232a7d3d SHA-256: 5cab3671c78f857eaa597eeb184ff470b7e031a63eed924af95850b485e5bb5a
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the dynamic DNS domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a mechanism to distribute further malicious content. The ML classifier also flagged this PDF as malicious, supporting the suspicious nature of the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6099097092099095/Elections-Electoral-Systems-and-Volatil-by-Gianfranco-Baldini.pdf
    • http://loaminoo.linkpc.net/5097094093094094/Parties-and-Elections-in-America-The-Electoral-Process-by-L-Maisel.pdf
    • http://loaminoo.linkpc.net/5097094093095099/Parties-and-Elections-in-America-The-Electoral-Process-by-Mark-D-Brewer.pdf
    • http://loaminoo.linkpc.net/5097094095092099/Electoral-Systems-Paradoxes-Assumptions-and-Procedures-by-Dan-S-Felsenthal.pdf
    • http://loaminoo.linkpc.net/5092090091092091/Making-Votes-Count-Strategic-Coordination-in-the-World-s-Electoral-Systems-by-Gary-W-Cox.pdf
    • http://loaminoo.linkpc.net/8094093091098090/Federal-Electoral-Districts-Representation-Order-of-1996-Circonscriptions-Electorales-Federales-Decret-de-Representation-Electorale-de-1996-by-Elections-Canada.pdf
    • http://loaminoo.linkpc.net/8094093091099094/Federal-Electoral-Districts-Representation-Order-of-1996-Circonscriptions-Electorales-Federales-Decret-de-Representation-Electorale-de-1996-by-Elections-Canada.pdf
    • http://loaminoo.linkpc.net/5097094095091099/Jaffna-District-Jaffna-Electoral-District-Thunnalai-Kayts-Electoral-District-Vaddukoddai-Electoral-District-Kopay-Electoral-District-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/5097094093095091/Democracy-and-the-Politics-of-Electoral-System-Choice-Engineering-Electoral-Dominance-by-Amel-Ahmed.pdf
    • http://loaminoo.linkpc.net/5097094093095098/Political-Parties-and-Electoral-Change-Party-Responses-to-Electoral-Markets-by-Peter-Mair.pdf
    • http://loaminoo.linkpc.net/6099097092099097/Hist-rias-do-Tempo-Vol-til-by-Adelino-Torres.pdf
    • http://loaminoo.linkpc.net/1090091090099091096/Murano-A-History-of-Glass-by-Gianfranco-Toso.pdf
    • http://loaminoo.linkpc.net/5099092092093097/Lire-Didier-Daeninckx-by-Gianfranco-Rubino.pdf
    • http://loaminoo.linkpc.net/5097094093090093/Modeling-and-Managing-Interdependent-Complex-Systems-of-Systems-by-Yacov-Y-Haimes.pdf
    • http://loaminoo.linkpc.net/1091092097093090091/Morocco-Bonechi-Golden-Book-Collection-by-Anna-Baldini.pdf
    • http://loaminoo.linkpc.net/1091092097092098097/Captain-Algernon-Fisk-and-the-Incident-at-Pluto-by-James-Baldini.pdf
    • http://loaminoo.linkpc.net/1091092097092098093/Carta-canta---Zitti-tutti---In-fondo-a-destra-by-Raffaello-Baldini.pdf
    • http://loaminoo.linkpc.net/1091096097092097096/St-Peter-s-Basilica---The-Sistine-chapel-The-Raphael-rooms---Art-and-light-by-Gianfranco-Crimi.pdf
    • http://loaminoo.linkpc.net/7099099094098091/Unifying-Themes-in-Complex-Systems-VII-Proceedings-of-the-Seventh-International-Conference-on-Complex-Systems-by-Ali-A-Minai.pdf
    • http://loaminoo.linkpc.net/1090097090094091097/The-American-Elections-of-2012-by-Janet-M-Box-Steffensmeier.pdf