Malicious PDF — malware analysis report

Static analysis result for SHA-256 c1713d3f718d13a0…

MALICIOUS

PDF

23.1 KB Created: 2019-05-07 03:35:13 +01:00 Authoring application: mPDF 5.7
MD5: 0ac40f577f7b80f5cf04169b8337f7c6 SHA-1: 62f0a1edd784d3342c416eecadc69049c2691231 SHA-256: c1713d3f718d13a0e9f1fd6aab7aa5cdee5098e6733f9d3193fc2f70621ef7bf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDFs hosted on the loaminoo.linkpc.net domain. This behavior is indicative of a link farm or SEO poisoning attack, designed to drive traffic to malicious or misleading content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9090095095099093/Kambodscha-Land-Der-Sanften-Morder-Ein-Bericht-Aus-Indochina-by-Michael-Sontheimer.pdf
    • http://loaminoo.linkpc.net/6092091099098096/Kambodscha-Demokratisches-Kampuchea-Rote-Khmer-Tribunal-Angkung-the-Killing-Fields---Schreiendes-Land-Banteay-Chhmar-Flagge-Kambodschas-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/1091092097097096091/Gl-serne-W-nde-Bericht-zur-Benachteiligung-nichtreligi-ser-Menschen-in-Deutschland-by-Michael-Bauer.pdf
    • http://loaminoo.linkpc.net/1090096093098099093/18-Tonmeistertagung-Karlsruhe-1994-International-Convention-on-Sound-Design-Vom-15-Bis-18-November-1994-Bericht-by-Michael-Dickreiter.pdf
    • http://loaminoo.linkpc.net/7098095095098098/Will-s-Way-by-Lee-Ann-Sontheimer-Murphy.pdf
    • http://loaminoo.linkpc.net/9090095096090094/Der-Elefantenfl-sterer-Mein-Leben-mit-den-sanften-Riesen-und-was-sie-mir-beibrachten-by-Anthony-Lawrence.pdf
    • http://loaminoo.linkpc.net/6092098098091/Buying-the-Land-Selling-the-Land-Govts-Maori-Land-in-the-North-Island-1865-1921-by-Richard-Boast.pdf
    • http://loaminoo.linkpc.net/8093091090093091/End-of-a-War-Indochina-1954-by-Philippe-Devillers.pdf
    • http://loaminoo.linkpc.net/1090099092092093095/In-the-Company-of-Gods-Essays-in-Memory-of-Gunther-Dietz-Sontheimer-by-Heidrun-Br-ckner.pdf
    • http://loaminoo.linkpc.net/1091096092093094094/Laos-Keystone-Of-Indochina-by-Arthur-J-Dommen.pdf
    • http://loaminoo.linkpc.net/6099099092092099/Andr-Malraux-The-Indochina-Adventure-by-Walter-G-Langlois.pdf
    • http://loaminoo.linkpc.net/9093096092099096/Land-s-End-ein-Spaziergang-in-Provincetown-by-Michael-Cunningham.pdf
    • http://loaminoo.linkpc.net/2099097096099093/The-Super-Spuds-4---Over-Land-and-Sea-by-Michael-Diack.pdf
    • http://loaminoo.linkpc.net/9095095096091091/Land-der-Mythen-6-Das-sechste-Buch-by-Michael-Peinkofer.pdf
    • http://loaminoo.linkpc.net/3094090098098091/Wintergreen-Listening-to-the-Land-s-Heart-by-Robert-Michael-Pyle.pdf
    • http://loaminoo.linkpc.net/4091099098097095/Drugs-Oil-amp-War-The-United-States-in-Afghanistan-Colombia-amp-Indochina-by-Peter-Dale-Scott.pdf
    • http://loaminoo.linkpc.net/9098096098096095/Land-of-Promise-An-Economic-History-of-the-United-States-by-Michael-Lind.pdf
    • http://loaminoo.linkpc.net/5096091096092099/We-Are-Coming-Unafraid-The-Jewish-Legions-and-the-Promised-Land-in-the-First-World-War-by-Michael-Keren.pdf
    • http://loaminoo.linkpc.net/1090090095092096095/Land-Contract-Homes-The-Top-10-Mistakes-Home-Buyers-Make-And-How-to-Avoid-Them-by-Michael-Delaware.pdf
    • http://loaminoo.linkpc.net/8098097094093099/Purple-Squirrel-Stand-Out-Land-Interviews-and-Master-the-Modern-Job-Market-by-Michael-B-Junge.pdf
    • http://loaminoo.linkpc.net/1090096093098099093/18-Tonmeistertagung-Karlsruhe-1994-International-Conv