Malicious PDF — malware analysis report

Static analysis result for SHA-256 78dc06c1eeca144f…

MALICIOUS

PDF

17.9 KB Created: 2019-05-02 01:44:39 +01:00 Authoring application: mPDF 5.7
MD5: ad4179ec20bd0566efe8747ca838f609 SHA-1: 7e5964fce6960e476a9f80aef946cdb47f21911c SHA-256: 78dc06c1eeca144f523978d99c60c44441d2fb45f3d35f3d4941b91310e3d666
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a redirection scheme, likely intended to drive traffic or potentially distribute further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090099099094093095/Mick-Murphy-s-Law-A-Mick-Murphy-Key-West-Mystery-by-Michael-Haskins.pdf
    • http://loaminoo.linkpc.net/1090099099096096091/To-Beat-the-Devil-A-Mick-Murphy-Key-West-Mystery-by-Michael-Haskins.pdf
    • http://loaminoo.linkpc.net/1094099091091094/All-That-Glitters-A-Jake-amp-Laura-Mystery-2-by-Michael-Murphy.pdf
    • http://loaminoo.linkpc.net/1094099094090096/Wings-in-the-Dark-A-Jake-amp-Laura-Mystery-3-by-Michael-Murphy.pdf
    • http://loaminoo.linkpc.net/1091094096091098090/Bj-rk-An-Illustrated-Biography-by-Mick-St-Michael.pdf
    • http://loaminoo.linkpc.net/1090090098092094/Mick-Charger-Murder-by-Cop-by-Michael-Atencio.pdf
    • http://loaminoo.linkpc.net/1091098094097097090/Ruhe-in-Fetzen-Ein-Fall-f-r-Mrs-Murphy-Ein-Mrs--Murphy-Krimi-2-by-Rita-Mae-Brown.pdf
    • http://loaminoo.linkpc.net/1091098094098097092/Die-Katze-l-sst-das-Mausen-nicht-Ein-Fall-f-r-Mrs-Murphy-Ein-Mrs--Murphy-Krimi-10-by-Rita-Mae-Brown.pdf
    • http://loaminoo.linkpc.net/1090099099094094091/Mick-Abruzzo-s-Story-Blackbird-Sisters-Mystery-0-5-by-Nancy-Martin.pdf
    • http://loaminoo.linkpc.net/8097096094092094/Die-Katze-l-sst-das-Mausen-nicht-Maus-im-Aus-Ein-Fall-f-r-Mrs-Murphy-Catch-As-Cat-Can-Tail-Of-The-Tip-Off-Mrs-Murphy-10-11-by-Rita-Mae-Brown.pdf
    • http://loaminoo.linkpc.net/1091095098097096092/Murphy-und-das-Grauen-D-monenj-ger-Murphy-by-Earl-Warren.pdf
    • http://loaminoo.linkpc.net/4098098093099097/Murphy-s-Law-Molly-Murphy-1-by-Rhys-Bowen.pdf
    • http://loaminoo.linkpc.net/2097092097095092/Murphy-s-Law-Molly-Murphy-1-by-Rhys-Bowen.pdf
    • http://loaminoo.linkpc.net/1091095098096098098/Murphy-und-die-Templer-D-monenj-ger-Murphy-by-Ann-Murdoch.pdf
    • http://loaminoo.linkpc.net/4091096098095096/I-Am-Sacajawea-I-Am-York-Our-Journey-West-with-Lewis-and-Clark-by-Claire-Rudolf-Murphy.pdf
    • http://loaminoo.linkpc.net/2093090099091090/Cat-of-the-Century-A-Mrs-Murphy-Mystery-by-Rita-Mae-Brown.pdf
    • http://loaminoo.linkpc.net/1092098091099095/In-a-Time-of-War-The-Proud-and-Perilous-Journey-of-West-Point-s-Class-of-2002-by-Bill-Murphy-Jr-.pdf
    • http://loaminoo.linkpc.net/9097090096098090/Blueprints-Psychiatry-by-Michael-J-Murphy.pdf
    • http://loaminoo.linkpc.net/3093094096090095/Cat-on-the-Edge-A-Joe-Grey-Mystery-by-Shirley-Rousseau-Murphy.pdf
    • http://loaminoo.linkpc.net/3093094097097098/Cat-Under-Fire-A-Joe-Grey-Mystery-by-Shirley-Rousseau-Murphy.pdf