Malicious PDF — malware analysis report

Static analysis result for SHA-256 7456380e1e3adfbd…

MALICIOUS

PDF

16.4 KB Created: 2019-05-02 00:53:15 +01:00 Authoring application: mPDF 5.7
MD5: 4cc341e134d3f87d5e04f9cf1daf912e SHA-1: c0411d9db15182937caf137f2dab88b2a0dcd98f SHA-256: 7456380e1e3adfbd7ca41e86bda4839a7dcd02c970bb003e02a27736a295e4b6
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of links to external PDF files, many of which are hosted on the dynamic DNS domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a method to distribute malicious content indirectly. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097097097099096/Confessions-of-a-Philosopher-by-J-A-Stevens.pdf
    • http://loaminoo.linkpc.net/9097093094093095/Confessions-of-a-Frigid-Man-A-Philosopher-s-Journey-into-the-Hidden-Layers-of-Men-s-Sexuality-by-Takeshi-Morisato.pdf
    • http://loaminoo.linkpc.net/6090092094092092/Confessions-of-a-Philosopher-A-Personal-Journey-Through-Western-Philosophy-from-Plato-to-Popper-by-Bryan-Magee.pdf
    • http://loaminoo.linkpc.net/4098091097099090/Confessions-of-a-Hollywood-Star-Confessions-of-a-Teenage-Drama-Queen-3-by-Dyan-Sheldon.pdf
    • http://loaminoo.linkpc.net/4090095096093095/Confessions-of-an-Angry-Girl-Confessions-1-by-Louise-Rozett.pdf
    • http://loaminoo.linkpc.net/4094091096090090/Confessions-of-a-Murder-Suspect-Confessions-1-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/1092099095094096/Confessions-of-a-Murder-Suspect-Confessions-1-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/6099092094097092/Confessions-of-a-Klutz-Confessions-1-by-Abigail-Davies.pdf
    • http://loaminoo.linkpc.net/1099094098090091/Confessions-of-a-Virgin-Sex-Columnist-Confessions-1-by-Kay-Marie.pdf
    • http://loaminoo.linkpc.net/3090099097096092/MALEDICTION-Rise-of-the-Crimson-Confessions-Crimson-Confessions-1-by-J-D-Lexx.pdf
    • http://loaminoo.linkpc.net/3099093092098094/Letters-of-Wallace-Stevens-by-Wallace-Stevens.pdf
    • http://loaminoo.linkpc.net/2097095095098091/Poems-Wallace-Stevens-by-Wallace-Stevens.pdf
    • http://loaminoo.linkpc.net/1094099096093093/The-Philosopher-s-Kiss-by-Peter-Prange.pdf
    • http://loaminoo.linkpc.net/7099092091097/The-Philosopher-s-Pupil-by-Iris-Murdoch.pdf
    • http://loaminoo.linkpc.net/6090094097093096/The-Philosopher-s-Guide-by-Darrell-Maret.pdf
    • http://loaminoo.linkpc.net/5093099093096/The-Philosopher-Kings-Thessaly-2-by-Jo-Walton.pdf
    • http://loaminoo.linkpc.net/1090093098099098/The-Philosopher-s-Apprentice-by-James-K-Morrow.pdf
    • http://loaminoo.linkpc.net/1090090097097096091/The-Travel-Diary-of-a-Philosopher-by-Hermann-Keyserling.pdf
    • http://loaminoo.linkpc.net/9092095098094091/Schiller-as-Philosopher-A-Re-Examination-by-Frederick-C-Beiser.pdf
    • http://loaminoo.linkpc.net/2090098098091090/Harry-Potter-and-the-Philosopher-s-Stone-by-J-K-Rowling.pdf