Malicious PDF — malware analysis report

Static analysis result for SHA-256 5f09f5cb485a6fa2…

MALICIOUS

PDF

17.0 KB Created: 2019-04-30 03:34:20 +01:00 Authoring application: mPDF 5.7
MD5: 5a39e4465a124cc452ec4dd539741d02 SHA-1: 066ba81e73e8d441f5c2c7f167639ee60d60e5d0 SHA-256: 5f09f5cb485a6fa28e6e673839b3f99597e564c171ef612300a7d9c9d4a2123b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links pointing to external PDF files, many of which are hosted on the dynamic DNS domain loaminoo.linkpc.net. This heuristic firing suggests a link farm or a method to distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4090093098094/Slam-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1090091093098092094/A-Long-Way-Down-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/4091093091091092/Not-A-Star-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1090091096093096093/A-Long-Way-Down-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/7091096097094093/Everyone-s-Reading-Bastard-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/3092094095096/High-Fidelity-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/8091099094094096/Alta-fidelidade-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/7090099094095/High-Fidelity-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/4096098094090096/Fever-Pitch-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/3092095096096099/Not-a-Star-and-Otherwise-Pandemonium-Stories-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/3091094090096093/Not-a-Star-and-Otherwise-Pandemonium-Stories-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1091090099096090093/Weniger-reden-und-fter-mal-in-die-Badewanne---Mein-Leben-als-Leser-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/2097091094099099/Books-Movies-Rhythm-Blues-Twenty-Years-of-Writing-About-Film-Music-and-Books-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/3093091094096095/Good-Thing-Bad-Thing-50-Reasons-3-by-Nick-Alexander.pdf
    • http://loaminoo.linkpc.net/1091096099098092097/Oxford-Advanced-Learner-s-Dictionary-by-A-S-Hornby.pdf
    • http://loaminoo.linkpc.net/7095097091094099/Toronto-and-the-Maple-Leafs-A-City-and-Its-Team-by-Lance-Hornby.pdf
    • http://loaminoo.linkpc.net/2098095094096099/The-Secret-Life-of-the-Love-Song-and-The-Flesh-Made-Word-Two-Lectures-by-Nick-Cave-by-Nick-Cave.pdf
    • http://loaminoo.linkpc.net/9097094098093096/Nick-and-Tesla-s-Special-Effects-Spectacular-A-Mystery-with-Animatronics-Alien-Makeup-Camera-Gear-and-Other-Movie-Magic-You-Can-Make-Yourself-Nick-and-Tesla-5-by-Bob-Pflugfelder.pdf
    • http://loaminoo.linkpc.net/4096099090093092/Nick-amp-Greg-The-Nick-amp-Greg-Books-Book-1-by-John-Roman-Baker.pdf
    • http://loaminoo.linkpc.net/1090090096098096092/The-Nick-Nolte-Handbook---Everything-You-Need-to-Know-about-Nick-Nolte-by-Skyler-Koch.pdf