Malicious PDF — malware analysis report

Static analysis result for SHA-256 daa88efefc7534a7…

MALICIOUS

PDF

17.3 KB Created: 2019-05-04 12:33:34 +01:00 Authoring application: mPDF 5.7
MD5: 343385b5f8e8e3a10421b9a42987dc8f SHA-1: d88ce73b1bd69bd991491d5ebe69b45a5c8934df SHA-256: daa88efefc7534a7a7b07c3ffacd36497cff2d41baa34dc0f85083ac9dbd8e0e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files hosted on the 'loaminoo.linkpc.net' domain. This heuristic, combined with the ML classifier, strongly suggests a malicious intent to redirect users to potentially harmful content. No scripts were extracted, and the document body was heavily corrupted, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5096097096098097/Nathaniel-Hawthorne-s-The-Scarlet-Letter-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/1090094091097097096/The-Scarlet-Letter-with-eBook-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/8095092098098096/THE-SCARLET-LETTER-Illustrated-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/6094093090096093/The-Scarlet-Letter-and-the-Blithedale-Romance-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/1099090095096093/The-Scarlet-Letter-amp-the-House-of-the-Seven-Gables-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/1091090095093094091/The-Scarlet-Letter-with-Additional-Material-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/9095099090095098/The-Scarlet-Letter-and-Related-Readings-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/8092097091093098/The-Scarlet-Letter---Full-Version-Annotated-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/8093098091097096/The-Scarlet-Letter-Audio-Book-Series---6-CD-Set-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/7095096090098097/The-Scarlet-Letter-Annotated-with-Study-Helps-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/7091095095090090/The-Scarlet-Letter-Bridge-Bilingual-Classics-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/7097090099092099/The-Scarlet-Letter-illustrated-Deluxe-Edition-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/5094090099096090/The-Scarlet-Letter-Golden-Illustrated-Classics-Comes-with-a-Free-Audiobook-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/7095091094097093/The-Scarlet-Letter-Centaurs-Classics-The-100-greatest-novels-of-all-time---39-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/5097094091090091/The-Scarlet-Letter---Original-February-1850-Uncensored-Version-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/8095098091090092/The-Scarlet-Letter-A-Romance-Burt-s-Library-of-the-World-s-Best-Books-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/3098096090095094/The-Selected-Short-Stories-of-Nathaniel-Hawthorne-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/9091093091096095/The-House-of-the-Seven-Gables-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/5093099092099090/The-House-of-the-Seven-Gables-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/6099092097096097/The-Ancestral-Footstep-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/709709