Malicious PDF — malware analysis report

Static analysis result for SHA-256 ede86314b5137a6a…

MALICIOUS

PDF

19.6 KB Created: 2019-05-02 00:41:32 +01:00 Authoring application: mPDF 5.7
MD5: 049eed5eef043f50f69ab0d47e8b45f0 SHA-1: 3820914c1013c931f5bb2989ce755d2fc3b02987 SHA-256: ede86314b5137a6a2385608ee9536e246c1a751e181098eedbf6d322e148169e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs pointing to external PDF files, constituting a link farm. The document body, though heavily obfuscated, contains these URLs, suggesting the primary intent is to redirect users to a collection of other documents hosted on the 'loaminoo.linkpc.net' domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096092093098090/Dare-To-Dream-25-Extraordinary-Lives-by-Sandra-McLeod-Humphrey.pdf
    • http://loaminoo.linkpc.net/4098099090091090/Making-Modern-Lives-Subjectivity-Schooling-and-Social-Change-by-Julie-McLeod.pdf
    • http://loaminoo.linkpc.net/3098093090093095/The-Extraordinary-Colours-of-Auden-Dare-by-Zillah-Bethell.pdf
    • http://loaminoo.linkpc.net/3099097091095096/The-Extraordinary-Colors-of-Auden-Dare-by-Zillah-Bethell.pdf
    • http://loaminoo.linkpc.net/5096096095/How-Dare-the-Sun-Rise-Memoirs-of-a-War-Child-by-Sandra-Uwiringiyimana.pdf
    • http://loaminoo.linkpc.net/2090099098090095/Dare-2-Dream-by-Ashley-S-Clancy.pdf
    • http://loaminoo.linkpc.net/9093098092093095/The-Best-Advice-I-Ever-Got-Lessons-from-Extraordinary-Lives-by-Katie-Couric.pdf
    • http://loaminoo.linkpc.net/1092092096093095/If-We-Dare-to-Dream-Evans-Family-1-by-Collette-Scott.pdf
    • http://loaminoo.linkpc.net/5091097095097098/Lives-of-Extraordinary-Women-Rulers-Rebels-by-Kathleen-Krull.pdf
    • http://loaminoo.linkpc.net/1091095090091093096/School-Days-According-to-Humphrey-According-to-Humphrey-7-by-Betty-G-Birney.pdf
    • http://loaminoo.linkpc.net/2095090098098091/Running-for-Their-Lives-The-Extraordinary-Story-of-Britain-s-Greatest-Ever-Distance-Runners-by-Mark-Whitaker.pdf
    • http://loaminoo.linkpc.net/4091093097099091/The-American-Dream-Revisited-Ordinary-People-Extraordinary-Results-by-Gary-Sirak.pdf
    • http://loaminoo.linkpc.net/1091095090091094096/Winter-According-to-Humphrey-According-to-Humphrey-9-by-Betty-G-Birney.pdf
    • http://loaminoo.linkpc.net/1091095090091093094/Surprises-According-to-Humphrey-According-to-Humphrey-4-by-Betty-G-Birney.pdf
    • http://loaminoo.linkpc.net/1091095090091095090/Imagination-According-to-Humphrey-According-to-Humphrey-11-by-Betty-G-Birney.pdf
    • http://loaminoo.linkpc.net/3094092093094095/The-Queen-of-Katwe-A-Story-of-Life-Chess-and-One-Extraordinary-Girl-s-Dream-of-Becoming-a-Grandmaster-by-Tim-Crothers.pdf
    • http://loaminoo.linkpc.net/3090096094093097/Gold-in-the-Water-The-True-Story-of-Ordinary-Men-and-Their-Extraordinary-Dream-of-Olympic-Glory-by-P-H-Mullen-Jr-.pdf
    • http://loaminoo.linkpc.net/8091098090099095/Into-the-Woods-John-James-Audubon-Lives-His-Dream-by-Robert-Burleigh.pdf
    • http://loaminoo.linkpc.net/4094090097096093/Dream-Brother-The-Lives-and-Music-of-Jeff-and-Tim-Buckley-by-David-Browne.pdf
    • http://loaminoo.linkpc.net/9099090094097094/Find-Your-Extraordinary-Dream-Bigger-Live-Happier-Achieve-Success-on-Your-Own-Terms-by-Embracing-the-Entrepreneurial-Spirit-in-You-by-Jessica-DiLullo-Herrin.pdf