Malicious PDF — malware analysis report

Static analysis result for SHA-256 92d6acc796fcf3d3…

MALICIOUS

PDF

17.2 KB Created: 2019-04-30 05:42:58 +01:00 Authoring application: mPDF 5.7
MD5: c15bceadf7d0238d59e09ec4b46f550b SHA-1: 12198c4aa26d1d0e5afc4a4dccbf334d7d37f6af SHA-256: 92d6acc796fcf3d3226cc1f09e71b3cdf01e80daf9c18f1ef92d8b70fa765f8a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a critical heuristic for containing a link farm with numerous external links, predominantly to numeric slugs on the 'loaminoo.linkpc.net' domain. While the document body text is heavily corrupted, the presence of a large number of links suggests a deceptive intent, likely to direct users to malicious content or phishing sites. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6096098094090091/Film-as-a-Subversive-Art-by-Amos-Vogel.pdf
    • http://loaminoo.linkpc.net/2097092091092095/The-End-of-Religion-Encountering-the-Subversive-Spirituality-of-Jesus-by-Bruxy-Cavey.pdf
    • http://loaminoo.linkpc.net/1098099099096094/Subversive-Sabbath-The-Surprising-Power-of-Rest-in-a-Nonstop-World-by-A-J-Swoboda.pdf
    • http://loaminoo.linkpc.net/9097095096098094/Parables-as-Subversive-Speech-Jesus-as-Pedagogue-of-the-Oppressed-by-William-R-Herzog-II.pdf
    • http://loaminoo.linkpc.net/1091098092099095093/The-James-Tiptree-Award-Anthology-4-Subversive-Stories-about-Sex-and-Gender-by-Karen-Joy-Fowler.pdf
    • http://loaminoo.linkpc.net/4094097090096095/Subversive-Words-Public-Opinion-In-Eighteenth-Century-France-by-Arlette-Farge.pdf
    • http://loaminoo.linkpc.net/2099098096098090/A-Field-Guide-to-Demons-Fairies-Fallen-Angels-and-Other-Subversive-Spirits-by-Carol-K-Mack.pdf
    • http://loaminoo.linkpc.net/1091095090098098098/How-Dirty-Girls-Get-Clean-An-Anthology-of-Wicked-Woman-Writes-Art-and-Subversive-Scholarship-by-Rene-Diedrich.pdf
    • http://loaminoo.linkpc.net/2093090092093/Polio-An-American-Story-by-David-M-Oshinsky.pdf
    • http://loaminoo.linkpc.net/4096090093093098/Thank-You-and-Ok-An-American-Zen-Failure-in-Japan-by-David-Chadwick.pdf
    • http://loaminoo.linkpc.net/8098093092095/Mellon-An-American-Life-by-David-Cannadine.pdf
    • http://loaminoo.linkpc.net/1092090090095090/The-American-Dream-HisStory-in-the-Making-by-David-Lee-Windecher.pdf
    • http://loaminoo.linkpc.net/1097092098099092/The-Myth-of-American-Religious-Freedom-by-David-Sehat.pdf
    • http://loaminoo.linkpc.net/5092091092093095/The-Dutch-American-Farm-by-David-Steven-Cohen.pdf
    • http://loaminoo.linkpc.net/1099094098097091/Benjamin-Lincoln-And-The-American-Revolution-by-David-B-Mattern.pdf
    • http://loaminoo.linkpc.net/7095092093094090/David-Mamet-and-American-Macho-by-Arthur-Holmberg.pdf
    • http://loaminoo.linkpc.net/5093097094093093/Electoral-Realignments-A-Critique-of-an-American-Genre-by-David-R-Mayhew.pdf
    • http://loaminoo.linkpc.net/7099099094093096/Late-Harvest-Rural-American-Writing-by-David-R-Pichaske.pdf
    • http://loaminoo.linkpc.net/1090092095095093/Race-and-Reunion-The-Civil-War-in-American-Memory-by-David-W-Blight.pdf
    • http://loaminoo.linkpc.net/1098099097090093/Eliminationists-How-Hate-Talk-Radicalized-the-American-Right-by-David-Neiwert.pdf
    • http://loaminoo.linkpc.net/2099098096098090/A-Field-Guide-to-Demons-Fairies