Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6abfca55115577e…

MALICIOUS

PDF

21.2 KB Created: 2019-05-02 07:02:56 +01:00 Authoring application: mPDF 5.7
MD5: c0b96b8b9a1c2dbfc7dc2eb17593136b SHA-1: d0c05acd7b607e986d391188dff9d676ef2edb94 SHA-256: f6abfca55115577e77df9ca7308a0e340650c0124e7b5ed3e08b3cb8d8caee14
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'loaminoo.linkpc.net'. This pattern is indicative of SEO poisoning or a link farm designed to drive traffic. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8096097093096095/The-Memoirs-of-General-Baron-de-Marbot-by-Jean-Baptiste-Antoine-Marcelin-baron-de-1782-1854-Marbot.pdf
    • http://loaminoo.linkpc.net/8096097093096098/The-Memoirs-of-General-the-Baron-de-Marbot-eBook-by-Marbot-Jean-Baptiste-Antoine-Marcelin.pdf
    • http://loaminoo.linkpc.net/8096097095092097/The-Memoirs-of-Baron-de-Marbot---late-Lieutenant-General-in-the-French-Army-Vol-I-by-Jean-Baptiste-Antoine-Marcelin-de-Marbot.pdf
    • http://loaminoo.linkpc.net/8096097093097093/M-moires-du-G-n-ral-Baron-de-Marbot-by-Baron-de-Jean-Baptiste-Antoine-Marcelin-Marbot.pdf
    • http://loaminoo.linkpc.net/8096097093096099/L-Aide-de-Camp-Marbot-Selections-from-the-M-moires-Du-G-n-ral-Baron-de-Marbot-by-Jean-Baptiste-Antoine-Marcelin-Marbot.pdf
    • http://loaminoo.linkpc.net/8096097094094090/The-Memoirs-of-Baron-de-Marbot---Late-Lieutenant-General-in-the-French-Army-Vol-I-by-Jean-Baptiste-de-Marbot.pdf
    • http://loaminoo.linkpc.net/8096097094092098/M-moires-du-g-n-ral-baron-de-Marbot-tome-1-by-G-n-ral-Baron-de-Marbot.pdf
    • http://loaminoo.linkpc.net/8096097093096090/The-Memoirs-of-Baron-de-Marbot-Late-Lieutenant---General-in-the-French-Army-by-Arthur-John-Butler.pdf
    • http://loaminoo.linkpc.net/8096097095092094/The-Memoirs-of-Baron-de-Marbot-Late-Lieutenant-General-in-the-French-Army-Volume-1-by-Arthur-John-Butler.pdf
    • http://loaminoo.linkpc.net/8096097093097095/The-Memoirs-of-Baron-de-Marbot-Vol-1-by-Arthur-John-Butler.pdf
    • http://loaminoo.linkpc.net/8096097093097090/The-Memoirs-of-Baron-de-Marbot---Scholar-s-Choice-Edition-by-Arthur-John-Butler.pdf
    • http://loaminoo.linkpc.net/8096097093097094/The-Memoirs-of-Baron-de-Marbot---Scholar-s-Choice-Edition-by-Arthur-John-Butler.pdf
    • http://loaminoo.linkpc.net/8094096096096095/Travels-in-India-by-Jean-Baptiste-Tavernier-Baron-of-Aubonne-by-V-Ball.pdf
    • http://loaminoo.linkpc.net/1091093098091092091/The-Landlocked-Baron-The-Six-Pearls-of-Baron-Ridlington-1-by-Sahara-Kelly.pdf
    • http://loaminoo.linkpc.net/3093095095090095/A-Rope-For-The-Baron-Baron-15-by-John-Creasey.pdf
    • http://loaminoo.linkpc.net/8090098093091099/Philosophie-de-L-Esprit-by-Jean-Louis-Vieillard-Baron.pdf
    • http://loaminoo.linkpc.net/7091092094094098/Brain-Dopaminergic-Systems-Imaging-with-Positron-Tomography-by-Jean-Claude-Baron.pdf
    • http://loaminoo.linkpc.net/2092098090094094/Marbot-A-Biography-by-Wolfgang-Hildesheimer.pdf
    • http://loaminoo.linkpc.net/1091093098092092099/Baron-s-by-D-G-Taylor.pdf
    • http://loaminoo.linkpc.net/9098097091094097/The-Art-of-Baron-Von-Lind-by-Baron-von-Lind.pdf
    • http://loaminoo.linkpc.net/8096097093096099/L-Aide-de-Camp-