Malicious PDF — malware analysis report

Static analysis result for SHA-256 f695f22c66dfd85c…

MALICIOUS

PDF

20.8 KB Created: 2019-05-01 17:15:14 +01:00 Authoring application: mPDF 5.7
MD5: b28d0f24f512ca4b6dd76a93d0d4be83 SHA-1: de5cfc575fb3fd14e0eb77500119b92371cf9ac7 SHA-256: f695f22c66dfd85cd95493ebf712eda62218785d067d3500c12514265e81590e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the document body is heavily obfuscated, the presence of numerous links suggests a potential distribution or SEO manipulation tactic. The primary IOCs are the domain loaminoo.linkpc.net and the associated URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/1090093090095093094/Come-Back-to-Sorrento-by-Dawn-Powell.pdf
    • http://loaminoo.linkpc.net/1090093090096098098/Sorrento-A-journey-with-a-view-The-road-to-the-Flow-of-Sorrento-with-a-traveler-s-guide-by-se-Thomassen.pdf
    • http://loaminoo.linkpc.net/1090093090096098097/The-Sorrento-Experience-Your-guide-to-holidays-in-Sorrento-and-the-Amalfi-coast-by-Gordon-Longworth.pdf
    • http://loaminoo.linkpc.net/1090093090097095098/Annual-Report-of-the-Town-Officers-of-Sorrento-Maine-For-the-Municipal-Year-Ending-February-21-1902-Also-the-Warrant-by-Sorrento-Maine.pdf
    • http://loaminoo.linkpc.net/2097099096090099/The-Shooting-of-Nancy-Howard-A-Journey-Back-to-Shore-by-Alice-Mathews.pdf
    • http://loaminoo.linkpc.net/9096094090095093/Back-Pain-Get-Your-Back-BACK---Your-Self-Help-Guide-on-How-to-Treat-Back-Pain-Naturally-and-Without-Drugs-Understanding-the-Anatomy-of-the-Back-Holistic-Pain-Holistic-Healing-Back-Pain-Book-1-by-Joschi-Schwarz.pdf
    • http://loaminoo.linkpc.net/3092091095090094/The-Back-of-Beyond-time-travel-gone-awry-by-Alan-R-Graham.pdf
    • http://loaminoo.linkpc.net/3094099093095096/Back-To-Back-Behind-Your-Back-2-by-Chelsea-M-Cameron.pdf
    • http://loaminoo.linkpc.net/4093096097092097/Breaking-Back-How-I-Lost-Everything-and-Won-Back-My-Life-by-James-Blake.pdf
    • http://loaminoo.linkpc.net/3092099096092097/Breaking-Back-How-I-Lost-Everything-and-Won-Back-My-Life-by-James-Blake.pdf
    • http://loaminoo.linkpc.net/5099096096096094/Back-on-Track-Shifting-Back-to-Grace-by-Ru-Dela-Torre.pdf
    • http://loaminoo.linkpc.net/1090093090096091091/Her-Man-in-Sorrento-by-Ann-M-Streetman.pdf
    • http://loaminoo.linkpc.net/1090093090095093097/Sorrento-by-Alice-Notley.pdf
    • http://loaminoo.linkpc.net/2098099096093091/Waterfront-Fists-And-Others-The-Collected-Fight-Stories-Of-Robert-E-Howard-by-Robert-E-Howard.pdf
    • http://loaminoo.linkpc.net/2098099099098094/Time-Burial-The-Collected-Fantasy-Tales-of-Howard-Wandrei-by-Howard-Wandrei.pdf
    • http://loaminoo.linkpc.net/1090093090095094094/Postcards-From-Sorrento-by-Josh-White.pdf
    • http://loaminoo.linkpc.net/5099091097093096/Naples-And-Sorrento-by-Michael-Leech.pdf
    • http://loaminoo.linkpc.net/1090093090096092093/Naples-amp-Sorrento-Travel-Map-by-Globetrotter.pdf
    • http://loaminoo.linkpc.net/1090093090098099098/The-Third-HGH-Symposium-Sorrento-May-1992-by-J-Girard.pdf
    • http://loaminoo.linkpc.net/1090093090095094097/Naples-and-Sorrento-by-Michael-Leech.pdf