Malicious PDF — malware analysis report

Static analysis result for SHA-256 c40fb922942b8714…

MALICIOUS

PDF

20.4 KB Created: 2019-05-02 02:18:33 +01:00 Authoring application: mPDF 5.7
MD5: ae89d8839ef5c97e5a4794b9b34c5c85 SHA-1: e6b809c8229c58ad3dfee4e5235c42089c267156 SHA-256: c40fb922942b87147bef702e8598edafb702e7c3e05f4817846f1be4517d9cbd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm designed to distribute malicious content. The primary attack pattern involves luring users to click on these links, which are hosted on the 'loaminoo.linkpc.net' domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3093099099094090/De-noodkreet-in-de-fles-Serie-Q-3-by-Jussi-Adler-Olsen.pdf
    • http://loaminoo.linkpc.net/1098096099099090/De-vrouw-in-de-kooi-Serie-Q-1-by-Jussi-Adler-Olsen.pdf
    • http://loaminoo.linkpc.net/4098093091096096/Liv-for-Liv-by-Jussi-Adler-Olsen.pdf
    • http://loaminoo.linkpc.net/4097090099095/The-Keeper-of-Lost-Causes-Department-Q-1-by-Jussi-Adler-Olsen.pdf
    • http://loaminoo.linkpc.net/1090090091099093090/Selfies-Der-siebte-Fall-f-r-das-Sonderdezernat-Q-in-Kopenhagen-Thriller-Carl-M-rck-7-by-Jussi-Adler-Olsen.pdf
    • http://loaminoo.linkpc.net/5094091097095091/Publication-Glenat-Album-Glenat-Serie-Glenat-Serie-Publiee-Dans-Circus-Serie-Publiee-Dans-Tcho-Tcho-Le-Bal-Du-Rat-Mort-One-Piece-Gunnm-Zblucops-Samson-amp-Neon-L-Ultime-Chimere-Liste-Des-Personnages-de-Titeuf-Mafalda-Ghost-in-the-Shell-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/9098098099092092/Adler-Speaks-The-Lectures-of-Alfred-Adler-by-Karen-A-Drescher.pdf
    • http://loaminoo.linkpc.net/7098099097095097/Myths-about-socialism-H-vard-Olsen-by-H-vard-Olsen.pdf
    • http://loaminoo.linkpc.net/9098098099091098/Jonathan-Adler-on-Happy-Chic-Accessorizing-by-Jonathan-Adler.pdf
    • http://loaminoo.linkpc.net/9090094095099099/Jussi-by-Anna-Lisa-Bjorling.pdf
    • http://loaminoo.linkpc.net/1091097091098099097/Delft-Advanced-School-for-Computing-and-Imaging-de-Porceleyne-Fles-Nieuwe-Kerk-Delfter-Donnerschlag-Technische-Universitat-Delft-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/9090094099094099/Finnskog-Og-Trollskap-Nitaha-Jussi-by-Dagfinn-Grnoset.pdf
    • http://loaminoo.linkpc.net/9090094098098092/The-Cold-War-A-History-in-Documents-and-Eyewitness-Accounts-by-Jussi-M-Hanhim-ki.pdf
    • http://loaminoo.linkpc.net/9090094098090090/Digital-Contagions-A-Media-Archaeology-of-Computer-Viruses-by-Jussi-Parikka.pdf
    • http://loaminoo.linkpc.net/9090094098099091/The-Spam-Book-On-Viruses-Porn-and-Other-Anomalies-from-the-Dark-Side-of-Digital-Culture-by-Jussi-Parikka.pdf
    • http://loaminoo.linkpc.net/3092090099094090/Just-Ask-Us-by-Sylvia-Olsen.pdf
    • http://loaminoo.linkpc.net/6095093095092/Tell-Me-a-Riddle-by-Tillie-Olsen.pdf
    • http://loaminoo.linkpc.net/5090091099090092/The-Touch-by-Lisa-Olsen.pdf
    • http://loaminoo.linkpc.net/1091097099091096/The-Touch-by-Lisa-Olsen.pdf
    • http://loaminoo.linkpc.net/6096094093093094/Exiles-of-Gaia-by-H-R-Olsen.pdf