Malicious PDF — malware analysis report

Static analysis result for SHA-256 64feb8d4c0379413…

MALICIOUS

PDF

19.9 KB Created: 2019-04-30 05:18:29 +01:00 Authoring application: mPDF 5.7
MD5: f9e5573eabbafa13ed829e2eae6e10ba SHA-1: e8e8850cb3fa84f09c0f7d0174b99e1fff725446 SHA-256: 64feb8d4c0379413073e732f04cb279f63e23e0126cc4f7dd0dc4b42303f6a7d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF files. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document. The embedded links likely serve as a lure to direct users to potentially malicious content hosted on the loaminoo.linkpc.net domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6095099090098095/Learning-from-the-Future-Competitive-Foresight-Scenarios-by-Liam-Fahey.pdf
    • http://loaminoo.linkpc.net/1091099097091090096/Strategic-Foresight-Learning-from-the-Future-by-Patricia-Lustig.pdf
    • http://loaminoo.linkpc.net/6092090090097097/The-Mystery-of-the-Shemitah-Updated-Edition-The-3-000-Year-Old-Mystery-That-Holds-the-Secret-of-America-s-Future-the-World-s-Future-and-Your-Future-by-Jonathan-Cahn.pdf
    • http://loaminoo.linkpc.net/3096090090093097/Embers-Foresight-1-by-Amy-Keen.pdf
    • http://loaminoo.linkpc.net/9092092094097/Foresight-Timesplash-3-by-Graham-Storrs.pdf
    • http://loaminoo.linkpc.net/1091095093098095095/Hocus-Pocus-Versus-the-Stinky-Pong-by-Mary-Anne-Fahey.pdf
    • http://loaminoo.linkpc.net/5090099096096093/Foresight-Cryptic-Spaces-1-by-Deen-Ferrell.pdf
    • http://loaminoo.linkpc.net/1096092097093092/Foresight-Helios-Oracles-1-by-Patti-Larsen.pdf
    • http://loaminoo.linkpc.net/4093097090093091/Licensed-to-Spy-With-the-Top-Secret-Military-Liaison-Mission-to-East-Germany-by-John-A-Fahey.pdf
    • http://loaminoo.linkpc.net/6095099091094097/Dare-to-Be-Different-Scenarios-1-2-by-Nicole-O-39-Dell.pdf
    • http://loaminoo.linkpc.net/6095099092093097/The-Marriage-Scenarios-by-Ingmar-Bergman.pdf
    • http://loaminoo.linkpc.net/5096090098094098/Learning-scikit-learn-Machine-Learning-in-Python-by-Ra-l-Garreta.pdf
    • http://loaminoo.linkpc.net/5090093098091091/All-Kinds-of-Minds-A-Young-Student-s-Book-about-Learning-Abilities-and-Learning-Disorders-by-Mel-Levine.pdf
    • http://loaminoo.linkpc.net/5094099098093099/Spontaneous-Communities-of-Learning-Learning-Ecosystems-SUrrounding-Virtual-Worlds-by-Lisa-Galarneau.pdf
    • http://loaminoo.linkpc.net/2091096097099097/Learning-To-Love-Again-A-Learning-Series-Book-3-by-Cynthia-P-O-39-Neill.pdf
    • http://loaminoo.linkpc.net/6095099091094098/Worst-Case-Scenarios-by-Cass-R-Sunstein.pdf
    • http://loaminoo.linkpc.net/1090093097090094094/E-Learning-and-the-Science-of-Instruction-Proven-Guidelines-for-Consumers-and-Designers-of-Multimedia-Learning-With-CDROM-by-Richard-E-Mayer.pdf
    • http://loaminoo.linkpc.net/3096099099090098/Learning-to-Let-Go-A-Learning-Series-Book-2-by-Cynthia-P-O-39-Neill.pdf
    • http://loaminoo.linkpc.net/6095099092097098/The-Doomsday-Book-Scenarios-for-the-End-of-the-World-by-Joel-Levy.pdf
    • http://loaminoo.linkpc.net/6095099092090090/Futurevision-Scenarios-for-the-world-in-2040-by-Richard-Watson.pdf