Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb1531d0f0cb7bf2…

MALICIOUS

PDF

18.6 KB Created: 2019-05-04 12:43:23 +01:00 Authoring application: mPDF 5.7
MD5: c3d5698bacfb8224e7198365c2b8f36d SHA-1: 88dcf681ffba0df007ac5514df18df03fe8f4e81 SHA-256: cb1531d0f0cb7bf23106910d8a99338ea1e007292bf4b08258a081b7125ad58e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6095090098099095/The-Invaders-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/6098098097099098/The-Time-Machine-Winner-of-the-Cover-Design-Challenge-on-Work-of-Art-The-Next-Great-Artist-by-Bravo-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/4092098099091096/Retief-Ambassador-to-Space-Retief-5-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/3094095090090090/The-Great-Bird-Flu-Hoax-The-Truth-They-Don-t-Want-You-to-Know-About-the-Next-Big-Pandemic-by-Joseph-Mercola.pdf
    • http://loaminoo.linkpc.net/9098090095095092/Worlds-of-the-Imperium-Imperium-1-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/5090094093096090/Retief-of-the-CDT-Retief-7-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/4090096095090096/Imperium-Imperium-1-3-by-Keith-Laumer.pdf
    • http://loaminoo.linkpc.net/8091097091093092/The-Time-Machine-The-Original-Time-Travel-Story-A-Short-Science-Fiction-Novel-about-Time-Travel-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/3090097095095098/Bread-Lover-s-Bread-Machine-Cookbook-A-Master-Baker-s-300-Favorite-Recipes-for-Perfect-Every-Time-Bread-From-Every-Kind-of-Machine-by-Beth-Hensperger.pdf
    • http://loaminoo.linkpc.net/9091091094091091/The-Time-Machine-Centaur-Classics-The-100-greatest-novels-of-all-time---96-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/7090090097099090/The-Ultimate-Time-Machine-A-Remote-Viewer-s-Perception-of-Time-amp-Predictions-for-the-New-Millennium-by-Joseph-McMoneagle.pdf
    • http://loaminoo.linkpc.net/5097094091098092/The-Time-Machine-The-Original-Time-Travel-Story-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/9096098092096098/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/5093094097094094/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/1091095091096095097/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/3097097092098099/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/5096098090094091/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/2099099090096099/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/6092095099096099/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/4099091098093091/The-Time-Machine-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/5090094093096090/Retief-of-the-CDT-Retief-7-by-K