Malicious PDF — malware analysis report

Static analysis result for SHA-256 ade86812cbfe065e…

MALICIOUS

PDF

20.8 KB Created: 2019-04-30 11:23:39 +01:00 Authoring application: mPDF 5.7
MD5: 2699d60ecb991443ec78f85d1597fc95 SHA-1: 64dc01a0e66ac9ec7803324962165001984b335b SHA-256: ade86812cbfe065ea8d59e8c91742992271ec300c7595e70dcda082a2dcbbfaf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'loaminoo.linkpc.net'. This is indicative of a link farm or SEO poisoning attack. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the immediate user-facing content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091094096096093093/Joh-Amos-Commenii-orbis-sensualium-pictus-hoc-est-omnium-principalium-in-mundo-rerum-amp-in-vita-actionum-pictura-amp-nomenclatura-Joh-Amos-Commenius-s-visible-world-by-Johann-Amos-Comenius.pdf
    • http://loaminoo.linkpc.net/1091094096096094096/Joh-Amos-Commenii-Orbis-Sensualium-Pictus-Hoc-Est-Omnium-Principalium-in-Mundo-Rerum-Et-in-Vita-Actionum-Pictura-Et-Nomenclatura-Joh-Amos-Commenius-s-Visible-World-or-a-Nomenclature-and-Pictures-of-All-the-Chief-Things-That-Are-in-the-World-and-by-Johann-Amos-Commenius.pdf
    • http://loaminoo.linkpc.net/9092096092098092/Evolutionary-Theory-and-Processes-Modern-Perspectives-Papers-in-Honour-of-Eviatar-Nevo-by-Eviatar-Nevo.pdf
    • http://loaminoo.linkpc.net/6093094093090091/The-Diary-Of-Amos-Lee-4-Lights-Camera-Superstar-The-Diary-of-Amos-Lee-4-by-Adeline-Foo.pdf
    • http://loaminoo.linkpc.net/5099091090097093/Neuland-by-Eshkol-Nevo.pdf
    • http://loaminoo.linkpc.net/1090091092094097/Homesick-by-Eshkol-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096092092097/Shakespeare-s-other-language-by-Ruth-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096092098094/Starving-at-the-feast-by-nevo-hadas.pdf
    • http://loaminoo.linkpc.net/9092096092099099/Miracle-in-Slovakia-by-Dana-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096092091098/Psychological-And-Behavioral-Aspects-Of-Diving-by-Baruch-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096093094091/how-to-hire-people-that-will-change-your-business-by-nevo-hadas.pdf
    • http://loaminoo.linkpc.net/9092096093099096/Art-Music-Love-Listening-and-Soulfulness-by-Matthew-Del-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096093099091/Population-Genetics-and-Ecology-by-Nevo-Eviatar-Karlin-Samuel.pdf
    • http://loaminoo.linkpc.net/9092096092098095/King-Abdallah-And-Palestine-A-Territorial-Ambition-by-Joseph-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096092098090/The-Nevo-Poor-poetry-written-at-2-A-M-Quagosphere-Book-1-by-Will-Elmore.pdf
    • http://loaminoo.linkpc.net/9092096092098099/King-Abdallah-and-Palestine-A-Territorial-Ambition-by-Joseph-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096092098096/We-Remember-Twenty-Four-Members-of-Kibbutz-Megido-Testify-by-Denise-Nevo.pdf
    • http://loaminoo.linkpc.net/9092096093095096/The-Metaphysics-of-Night-Recovering-Soul-Renewing-Humanism-by-Matthew-Del-Nevo.pdf
    • http://loaminoo.linkpc.net/5097096098096/My-Michael-by-Amos-Oz.pdf
    • http://loaminoo.linkpc.net/8091093098099099/Juifs-par-les-mots-by-Amos-Oz.pdf