Malicious PDF — malware analysis report

Static analysis result for SHA-256 d356cc6862277206…

MALICIOUS

PDF

16.8 KB Created: 2019-05-05 16:01:55 +01:00 Authoring application: mPDF 5.7
MD5: c05aa3367948abbd2dd05cdd2640ee96 SHA-1: 412911bdebce98e8eb37c0beee12627cd8035f15 SHA-256: d356cc6862277206c8686079778383f4f1f68ef1b1543e1b6d872270bc89c89a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the document body is heavily obfuscated, the presence of numerous links suggests a link farm or distribution mechanism. The primary IOCs are the URLs hosted on loaminoo.linkpc.net.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1094098096095097/Long-Walks-Last-Flights-and-Other-Strange-Journeys-by-Ken-Scholes.pdf
    • http://loaminoo.linkpc.net/1099099091097091/Long-Walks-in-the-Afternoon-Poems-by-Margaret-Gibson.pdf
    • http://loaminoo.linkpc.net/1090097092093096090/Das-Ende-kommt-zum-Schluss-Short-Stories-for-long-Journeys-by-Michael-Hegemann.pdf
    • http://loaminoo.linkpc.net/2096097095091094/A-Voyage-Long-and-Strange-On-the-Trail-of-Vikings-Conquistadors-Lost-Colonists-and-Other-Adventurers-in-Early-America-by-Tony-Horwitz.pdf
    • http://loaminoo.linkpc.net/1091095093091096090/The-Journeys-of-Jesus-A-Chronological-Geographical-and-Topographical-History-of-the-Journeys-of-Jesus-and-the-Twelve-Disciples-in-Palestine-by-Addison-Darre-Crabtre.pdf
    • http://loaminoo.linkpc.net/3092095099093093/Last-Flight-of-the-Goddess-by-Ken-Scholes.pdf
    • http://loaminoo.linkpc.net/1095096091096092/Lamentation-Psalms-of-Isaak-1-by-Ken-Scholes.pdf
    • http://loaminoo.linkpc.net/3094096096097098/Antiphon-Psalms-of-Isaak-3-by-Ken-Scholes.pdf
    • http://loaminoo.linkpc.net/3092095093098094/Looking-for-Truth-in-a-Wild-Blue-Yonder-by-Ken-Scholes.pdf
    • http://loaminoo.linkpc.net/6097098090094/A-Darkness-Strange-and-Lovely-Something-Strange-and-Deadly-2-by-Susan-Dennard.pdf
    • http://loaminoo.linkpc.net/8096095091/Flights-by-Olga-Tokarczuk.pdf
    • http://loaminoo.linkpc.net/1090099096096094090/Flights-of-Freedom-by-Ranga-Iyer.pdf
    • http://loaminoo.linkpc.net/8098093095094092/Flights-of-Love-Stories-by-Bernhard-Schlink.pdf
    • http://loaminoo.linkpc.net/8099096093096/Akiko-Flights-of-Fancy-by-Mark-Crilley.pdf
    • http://loaminoo.linkpc.net/3091094095091096/Strange-Versus-Lovecraft-by-Kevin-Strange.pdf
    • http://loaminoo.linkpc.net/6096099093094094/Leonardo-da-Vinci-Flights-of-the-Mind-by-Charles-Nicholl.pdf
    • http://loaminoo.linkpc.net/9099090093096/Natural-Flights-of-the-Human-Mind-by-Clare-Morrall.pdf
    • http://loaminoo.linkpc.net/1091092099097094/Flights-and-Chimes-and-Mysterious-Times-by-Emma-Trevayne.pdf
    • http://loaminoo.linkpc.net/4096099096095091/Flying-High-Freighter-Flights-2-by-Drew-Zachary.pdf
    • http://loaminoo.linkpc.net/4099095099095098/Knights-of-Desire-Flights-of-Fancy-2-by-Melodee-Aaron.pdf
    • http://loaminoo.linkpc.net/1095096091096092/Lamentation-Psalms-of-Isaak-1-by-Ken-Scholes.pd