Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e2c801e1eea7ae7…

MALICIOUS

PDF

15.8 KB Created: 2019-04-30 02:54:07 +01:00 Authoring application: mPDF 5.7
MD5: e3a510236d91a0ce5ad0d4199c506804 SHA-1: 4f0ac0ca2e371c3a12a977e2711903040cec4532 SHA-256: 5e2c801e1eea7ae7b52beebb0c46ad09e45dd0df2ae0e1e5f993e537b6676065
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the dynamic DNS domain 'loaminoo.linkpc.net'. This pattern is indicative of SEO poisoning or a link farm designed to drive traffic to potentially malicious content. The ML classifier also flagged this PDF as malicious with a high probability.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091099090099095094/Northern-Lights-A-Kid-s-Book-About-Aurora-Borealis-by-Nicholas-Eliott.pdf
    • http://loaminoo.linkpc.net/2093099090093097/The-Northern-Lights-The-True-Story-of-the-Man-Who-Unlocked-the-Secrets-of-the-Aurora-Borealis-by-Lucy-Jago.pdf
    • http://loaminoo.linkpc.net/2095092094098099/Aurora-In-Search-of-the-Northern-Lights-by-Melanie-Windridge.pdf
    • http://loaminoo.linkpc.net/6099094094095094/On-the-Aurora-Borealis-and-the-Aurora-Australis-by-Joseph-Lovering.pdf
    • http://loaminoo.linkpc.net/1091099090099095093/Swallows-a-kids-book-about-swallow-birds-by-Nicholas-Eliott.pdf
    • http://loaminoo.linkpc.net/1091099090098095098/The-Sleeping-Baby-by-Nicholas-Eliott.pdf
    • http://loaminoo.linkpc.net/2091093093091091/Let-the-Northern-Lights-Erase-Your-Name-by-Vendela-Vida.pdf
    • http://loaminoo.linkpc.net/3099096097097094/Let-the-Northern-Lights-Erase-Your-Name-by-Vendela-Vida.pdf
    • http://loaminoo.linkpc.net/4091096097094094/Between-the-Lies-Northern-Lights-Series-1-by-Joy-E-DeKok.pdf
    • http://loaminoo.linkpc.net/1091099090099094094/Barn-Owls-A-Kids-Book-About-Barn-Owls-by-Nicholas-Eliott.pdf
    • http://loaminoo.linkpc.net/6091091094094094/Northern-Lights-His-Dark-Materials-1-by-Philip-Pullman.pdf
    • http://loaminoo.linkpc.net/5098091093091/Northern-Lights-His-Dark-Materials-1-by-Philip-Pullman.pdf
    • http://loaminoo.linkpc.net/1091099094098091091/The-Alaskan-Catch-Northern-Lights-1-by-Beth-Carpenter.pdf
    • http://loaminoo.linkpc.net/5090094094092092/Northern-Lights-His-Dark-Materials-1-by-Philip-Pullman.pdf
    • http://loaminoo.linkpc.net/2095099090098097/Northern-Lights-His-Dark-Materials-1-by-Philip-Pullman.pdf
    • http://loaminoo.linkpc.net/1091099090099094096/Strength-Through-Dragons-and-Chinese-Proverbs-by-Nicholas-Eliott.pdf
    • http://loaminoo.linkpc.net/1099092090093094/Northern-Lights-The-Soccer-Trails-by-Michael-Arvaarluk-Kusugak.pdf
    • http://loaminoo.linkpc.net/4091090094093095/Under-the-Northern-Lights-Granite-Lake-Wolves-1-2-by-Vivian-Arend.pdf
    • http://loaminoo.linkpc.net/1090098099092093/The-Journey-of-Eleven-Moons-Northern-Lights-1-by-Bonnie-Leon.pdf
    • http://loaminoo.linkpc.net/2098092099095090/Transcendence-Aurora-Rising-Book-Three-Aurora-Rhapsody-3-by-G-S-Jennsen.pdf