Malicious PDF — malware analysis report

Static analysis result for SHA-256 e69ea1984c23dc4c…

MALICIOUS

PDF

22.4 KB Created: 2019-05-02 05:45:10 +01:00 Authoring application: mPDF 5.7
MD5: 284f570c7f39a0fae84368086965ecc3 SHA-1: b9e384cd4d0df7d16bed56fe91e58ca2ba6a0526 SHA-256: e69ea1984c23dc4c0cf88f511013d775ba470ef20cde68e27797f57945a50934
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, forming a link farm. The primary heuristic indicates this is a PDF SEO link farm, with 28 links pointing to external PDFs. The document body contains numerous URLs, all pointing to the same domain 'loaminoo.linkpc.net', suggesting a coordinated effort to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3099098099/Hogwarts-An-Incomplete-and-Unreliable-Guide-Pottermore-Presents-3-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/2093091095090099/Hogwarts-An-Incomplete-and-Unreliable-Guide-Pottermore-Presents-3-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/2096090094091092/Short-Stories-from-Hogwarts-of-Power-Politics-and-Pesky-Poltergeists-Pottermore-Presents-2-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/3099098094/Short-Stories-from-Hogwarts-of-Heroism-Hardship-and-Dangerous-Hobbies-Pottermore-Presents-1-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/1097095095095096/Short-Stories-from-Hogwarts-of-Heroism-Hardship-and-Dangerous-Hobbies-Pottermore-Presents-1-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/2095099090098099/The-Hogwarts-Collection-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/4094099095096094/Always-Unreliable-Unreliable-Memoirs-Falling-Towards-England-May-Week-Was-in-June-Unreliable-Memoirs-1-3-by-Clive-James.pdf
    • http://loaminoo.linkpc.net/9092099096096095/Mental-Floss-presents-In-the-Beginning-From-Big-Hair-to-the-Big-Bang-mental_floss-presents-a-Mouthwatering-Guide-to-the-Origins-of-Everything-by-Will-Pearson.pdf
    • http://loaminoo.linkpc.net/6093090091093098/Harry-Potter-and-the-Philosopher-s-Stone-4-Books-Bundle-Collection-By-J-K-Rowling-With-Gift-Journal-by-J-K-Rowling.pdf
    • http://loaminoo.linkpc.net/1091097091094090092/Showcase-Presents-DC-Comics-Presents-Superman-Team-Ups-Vol-1-by-Len-Wein.pdf
    • http://loaminoo.linkpc.net/1098096094097092/Brian-Aldiss-Presents-Britain-s-Leading-SF-Exponent-Presents-his-Favourite-Stories-by-Brian-W-Aldiss.pdf
    • http://loaminoo.linkpc.net/4090097093095091/The-Incomplete-Amorist-by-E-Nesbit.pdf
    • http://loaminoo.linkpc.net/1090092094090091/An-Incomplete-Education-by-Judy-Jones.pdf
    • http://loaminoo.linkpc.net/4097097095095097/The-Incomplete-Book-of-Running-by-Peter-Sagal.pdf
    • http://loaminoo.linkpc.net/1091096094096093091/Violet-Anime-incomplete-by-Elena-Munaretto.pdf
    • http://loaminoo.linkpc.net/5092098094090097/The-Deathly-Hallows-Lectures-The-Hogwarts-Professor-Explains-the-Final-Harry-Potter-Adventure-by-John-Granger.pdf
    • http://loaminoo.linkpc.net/3091094092094094/An-Incomplete-Revenge-Maisie-Dobbs-5-by-Jacqueline-Winspear.pdf
    • http://loaminoo.linkpc.net/2092099094099098/An-Incomplete-Revenge-Maisie-Dobbs-5-by-Jacqueline-Winspear.pdf
    • http://loaminoo.linkpc.net/4094095093097096/Incomplete-Short-Stories-and-Essays-by-Jamie-Berrout.pdf
    • http://loaminoo.linkpc.net/1091091093094097092/Sol-LeWitt-Incomplete-Open-Cubes-by-Nicholas-Baume.pdf
    • http://loaminoo.linkpc.net/1097095095095096/Short-Stories-from-Hogwarts-of-Heroism-Hardship-and-Dangerous-Hobbies-Pottermore-Presents-1-by-J-K-Row