Malicious PDF — malware analysis report

Static analysis result for SHA-256 5dce927e4f1fb4d4…

MALICIOUS

PDF

16.0 KB Created: 2019-05-02 01:21:09 +01:00 Authoring application: mPDF 5.7
MD5: d5a9df454833bc571f28b32095918d9f SHA-1: d1c843a4622bc23090e6d0ba5a3cf4490cdda9c3 SHA-256: 5dce927e4f1fb4d432ceecdc44101046743681146fb198d88972fa240b17efae
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the dynamic DNS domain 'loaminoo.linkpc.net'. This heuristic firing suggests a link farm or a method to distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5095090093092099/Fire-and-Water-Primeval-8-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/3095098090095091/Primeval-Magic-Demons-of-Fire-and-Night-3-by-C-N-Crawford.pdf
    • http://loaminoo.linkpc.net/5095090094099091/Doctor-Who-The-Yes-Men-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/5095090094096095/No-Rest-for-the-Wicked-Graceless-2-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/5095090093092095/Doctor-Who-The-Time-Travellers-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/5095090094093096/Doctor-Who-The-Uncertainty-Principle-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/5095090095090091/Sapphire-and-Steel-The-School-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/5095090094090095/Doctor-Who-The-Cold-Equations-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/5095090094094092/The-Wake-Bernice-Summerfield-42-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/3092097099092090/Doctor-Who-Short-Trips-The-History-of-Christmas-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/5095090093098098/Doctor-Who-Shadow-of-Death-Destiny-of-the-Doctor-2-by-Simon-Guerrier.pdf
    • http://loaminoo.linkpc.net/3091098096096095/Water-and-Fire-by-Demelza-Carlton.pdf
    • http://loaminoo.linkpc.net/6090094092092/Fire-amp-Water-by-Betsy-Graziani-Fasbinder.pdf
    • http://loaminoo.linkpc.net/1091097099098097095/Nicaragua-Water-Fire-by-Gioconda-Belli.pdf
    • http://loaminoo.linkpc.net/1090096097093/By-Fire-By-Water-by-Mitchell-James-Kaplan.pdf
    • http://loaminoo.linkpc.net/4099099099091095/Water-and-Fire-Elemental-Harmony-2-by-Rowan-McAllister.pdf
    • http://loaminoo.linkpc.net/5090096091093097/Fire-Water-World-Poems-by-Adrian-C-Louis.pdf
    • http://loaminoo.linkpc.net/2097098096091095/The-Island-Queen-Dethroned-by-Fire-and-Water-A-Tale-of-the-Southern-Hemisphere-by-R-M-Ballantyne.pdf
    • http://loaminoo.linkpc.net/6095090095096/Light-of-Honor-Primeval-Origins-Saga-2-by-B-A-Vonsik.pdf
    • http://loaminoo.linkpc.net/1091090092098097099/Earth-Air-Fire-Water-Pre-Christian-and-Pagan-Elements-in-British-Songs-Rhymes-and-Ballads-by-Robin-Skelton.pdf