Malicious PDF — malware analysis report

Static analysis result for SHA-256 795693ab37d5199c…

MALICIOUS

PDF

23.8 KB Created: 2019-05-01 13:54:28 +01:00 Authoring application: mPDF 5.7
MD5: 9cdf45d72a2f79bec296d7ebd25093dc SHA-1: 1453a52073cf4f502ec41a35764db94ea9cba975 SHA-256: 795693ab37d5199c94e350d7bcc495fafad59fa8b761991843b418e1d7b65c9c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the 'PDF_SEO_LINK_FARM' heuristic, which are disguised as academic papers. These links all point to the same domain, 'loaminoo.linkpc.net', suggesting a coordinated effort to drive traffic to potentially malicious or ad-filled websites. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090091090097099093/Ergodic-Theory-With-a-View-Towards-Number-Theory-by-Manfred-Einsiedler.pdf
    • http://loaminoo.linkpc.net/9096095096091097/Number-Theory-by-Helmut-Hasse.pdf
    • http://loaminoo.linkpc.net/1090098095092099092/A-Pathway-Into-Number-Theory-by-R-P-Burn.pdf
    • http://loaminoo.linkpc.net/4093096095097091/104-Number-Theory-Problems-From-the-Training-of-the-USA-IMO-Team-by-Titu-Andreescu.pdf
    • http://loaminoo.linkpc.net/1091099091091091095/Probabilistic-Number-Theory-II-Central-Limit-Theorems-by-P-D-Eliott.pdf
    • http://loaminoo.linkpc.net/8093097092092096/Introduction-to-the-Theory-of-the-Early-Universe-Cosmological-Perturbations-and-Inflationary-Theory-by-Dmitry-S-Gorbunov.pdf
    • http://loaminoo.linkpc.net/3096090096093093/The-Omega-Theory-Final-Theory-2-by-Mark-Alpert.pdf
    • http://loaminoo.linkpc.net/8090091098092090/Theory-and-Practice-of-Managed-Competition-in-Health-Care-Finance-Lectures-in-Economics-Theory-Institutions-Policy-by-Alain-C-Enthoven.pdf
    • http://loaminoo.linkpc.net/1090090093092090092/Combinatorial-Number-Theory-Proceedings-of-the-Integers-Conference-2007-Carrollton-Georgia-USA-October-24--27-2007-by-Bruce-Landman.pdf
    • http://loaminoo.linkpc.net/6090090090096091/Teacher-Identity-How-teachers-construct-their-identity-in-Higher-Professional-Education-A-grounded-theory-study-based-on-dialogical-self-theory-and-pattern-language-by-Rudy-Vandamme.pdf
    • http://loaminoo.linkpc.net/6090097094097090/Pi-Monads-And-The-Quasi-Circle-Theory-A-Theory-On-The-Circle-More-Appropriate-To-The-Space-Age-by-Lionel-Fabius.pdf
    • http://loaminoo.linkpc.net/8093097093090092/Harmony-Its-No-and-Practice-Its-Theory-Ts-Theory-by-Ebenezer-Prout-B-Prout.pdf
    • http://loaminoo.linkpc.net/1090093090098095094/SOFSEM-2004-Theory-and-Practice-of-Computer-Science-30th-Conference-on-Current-Trends-in-Theory-and-Practice-of-Computer-Science-Merin-Czech-Republic-2004-Lecture-Notes-in-Computer-Science-by-Peter-Van-Emde-Boas.pdf
    • http://loaminoo.linkpc.net/9099091095093093/Myth-and-the-Human-Sciences-Hans-Blumenberg-s-Theory-of-Myth-Hans-Blumenberg-s-Theory-of-Myth-by-Angus-Nicholls.pdf
    • http://loaminoo.linkpc.net/4099093091097095/After-Theory-by-Terry-Eagleton.pdf
    • http://loaminoo.linkpc.net/5095090097099092/The-Resistance-to-Theory-by-Paul-De-Man.pdf
    • http://loaminoo.linkpc.net/7092092099098090/The-Game-Theory-by-Uri-Bram.pdf
    • http://loaminoo.linkpc.net/1090099098093095/The-Everything-Theory-by-Dianne-F-Gray.pdf
    • http://loaminoo.linkpc.net/2094093094091093/The-Quantity-Theory-of-Insanity-by-Will-Self.pdf
    • http://loaminoo.linkpc.net/7097094092095098/Network-Theory-by-R-Boite.pdf