Malicious PDF — malware analysis report

Static analysis result for SHA-256 88049a2f1845d543…

MALICIOUS

PDF

14.3 KB Created: 2019-04-29 23:04:47 +01:00 Authoring application: mPDF 5.7
MD5: 094119aacbdc3f0c61e3dfb8877ae72e SHA-1: eda9617d749b13c46b235341d0ef9a10a5e1cb44 SHA-256: 88049a2f1845d5437d7d7a9ef5123740d80fbb4892c78b2396d8c3e2445aff34
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: User Execution

The PDF document was flagged by a machine learning classifier and contains a large number of embedded external links, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' specifically identifies this pattern, with the dominant host being 'loaminoo.linkpc.net'. While the extracted URLs are currently marked as benign, the overall structure and heuristic firings strongly suggest a malicious intent, likely to lure users to external sites or to mask the true nature of the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4093091098093095/The-Return-of-Dr-Fu-Manchu-by-Sax-Rohmer.pdf
    • http://loaminoo.linkpc.net/3094099098099099/The-Mystery-of-Dr-Fu-Manchu-by-Sax-Rohmer.pdf
    • http://loaminoo.linkpc.net/4093091098093098/The-Hand-of-Fu-Manchu-by-Sax-Rohmer.pdf
    • http://loaminoo.linkpc.net/4091094092098090/Manchu-by-Robert-S-Elegant.pdf
    • http://loaminoo.linkpc.net/8092091090096098/The-Power-of-Return-Return-to-Me-That-I-May-Return-to-You-by-John-Goyette.pdf
    • http://loaminoo.linkpc.net/9094096099098091/Gerhart-Hauptmann-by-Rolf-Rohmer.pdf
    • http://loaminoo.linkpc.net/9097095098097097/Amok-Wahn-Thriller-by-Henry-Rohmer.pdf
    • http://loaminoo.linkpc.net/5092094095090091/The-New-Wave-Truffaut-Godard-Chabrol-Rohmer-Rivette-by-James-Monaco.pdf
    • http://loaminoo.linkpc.net/9091096093090/The-Invisible-Hunters-Los-Cazadores-Invisibles-A-Legend-from-the-Mikito-Indians-of-Nicaragua-by-Harriet-Rohmer.pdf
    • http://loaminoo.linkpc.net/1098092093093092/Return-to-Newport-Return-to-Me-2-by-A-L-Parks.pdf
    • http://loaminoo.linkpc.net/1098092093094094/The-Return-Return-to-Me-1-by-A-L-Parks.pdf
    • http://loaminoo.linkpc.net/4091094096091098/The-Return-by-Lee-Olds.pdf
    • http://loaminoo.linkpc.net/4090094091098096/All-Who-Go-Do-Not-Return-by-Shulem-Deen.pdf
    • http://loaminoo.linkpc.net/1098092093090099/Return-of-the-Dapper-Men-by-Jim-McCann.pdf
    • http://loaminoo.linkpc.net/1090095098092098099/The-Return-by-Dinah-McCall.pdf
    • http://loaminoo.linkpc.net/4090090091095093/No-Return-by-Brett-Battles.pdf
    • http://loaminoo.linkpc.net/5092091098098094/Why-I-Return-to-Makoce-by-Lois-Red-Elk.pdf
    • http://loaminoo.linkpc.net/3099090092090095/About-a-Certain-Return-by-Samuel-Trenton.pdf
    • http://loaminoo.linkpc.net/3095097094091098/Return-to-Innocence-by-G-M-Frazier.pdf
    • http://loaminoo.linkpc.net/3098098096097091/The-Day-of-Their-Return-by-Poul-Anderson.pdf
    • http://loaminoo.linkpc.net/4091094096091098