Malicious PDF — malware analysis report

Static analysis result for SHA-256 f8b6779826311bcc…

MALICIOUS

PDF

32.9 KB Created: 2019-05-02 05:06:47 +01:00 Authoring application: mPDF 5.7
MD5: 2fe89fa44549d390f5a967e6a10e9a86 SHA-1: 5297b154a9b37e4872e8c10d014337aba2d684fd SHA-256: f8b6779826311bcc3968d72e30c51920cd378e4fa1fea66daa516f50780ee65e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on the `loaminoo.linkpc.net` domain. The ML_NYX_PDF_MALICIOUS heuristic also flagged this PDF with high confidence. The primary attack pattern observed is the creation of a link farm, likely intended to drive traffic or potentially host malicious content on the linked domains.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9890

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090090090095094/Fish-Into-Wine-The-Newfoundland-Plantation-in-the-Seventeenth-Century-by-Peter-E-Pope.pdf
    • http://loaminoo.linkpc.net/8094091097093098/Directory-Department-Store-Wine-Shops-amp-Wine-Stores-In-Major-U-S-Cities-Section-H-Supplement-To-World-Wine-Almanac-amp-Wine-Atlas-Complete-Wine-Buying-Guide-amp-Catalogue-Of-Wine-Labels-by-Grace-Jane-Trebor.pdf
    • http://loaminoo.linkpc.net/3096092096097098/Light-of-the-World-The-Pope-the-Church-and-the-Signs-of-the-Times---A-Conversation-with-Peter-Seewald-by-Pope-Benedict-XVI.pdf
    • http://loaminoo.linkpc.net/1091094095098094096/Italian-Guitar-Music-of-the-Seventeenth-Century-Battuto-and-Pizzicato-by-Lex-Eisenhardt.pdf
    • http://loaminoo.linkpc.net/1091090090094094095/The-Illustrated-Bartsch-Italian-Masters-of-the-Seventeenth-Century-by-John-T-Spike.pdf
    • http://loaminoo.linkpc.net/4095093099092094/Sodomy-and-the-Pirate-Tradition-English-Sea-Rovers-in-the-Seventeenth-Century-Caribbean-by-B-R-Burg.pdf
    • http://loaminoo.linkpc.net/1095099095099093/Global-Crisis-War-Climate-Change-and-Catastrophe-in-the-Seventeenth-Century-by-Geoffrey-Parker.pdf
    • http://loaminoo.linkpc.net/1096099092090093/Cartographies-of-Tsardom-The-Land-and-Its-Meanings-in-Seventeenth-Century-Russia-by-Valerie-A-Kivelson.pdf
    • http://loaminoo.linkpc.net/7090098093097099/Planting-and-Loving-Popular-Sexual-Mores-in-the-Seventeenth-Century-Chesapeake-by-Irmina-Wawrzyczek.pdf
    • http://loaminoo.linkpc.net/5091096097092090/True-Relations-Reading-Literature-and-Evidence-in-Seventeenth-Century-England-by-Frances-E-Dolan.pdf
    • http://loaminoo.linkpc.net/5091097095091097/The-Invention-of-Improvement-Information-and-Material-Progress-in-Seventeenth-Century-England-by-Paul-Slack.pdf
    • http://loaminoo.linkpc.net/7098099097095099/The-Great-Peace-of-Montreal-of-1701-French-Native-Diplomacy-in-the-Seventeenth-Century-by-Gilles-Havard.pdf
    • http://loaminoo.linkpc.net/5091097090098095/The-Practice-of-Piety-Puritan-Devotional-Disciplines-in-Seventeenth-Century-New-England-by-Charles-E-Hambrick-Stowe.pdf
    • http://loaminoo.linkpc.net/7092095098093098/Ish-noo-ju-lut-sche-or-The-eagle-of-the-Mohawks-A-tale-of-the-seventeenth-century-by-John-Linneaus-Edward-Whitridge-Shecut.pdf
    • http://loaminoo.linkpc.net/3099099097093097/The-Great-Plantation-A-Profile-of-Berkeley-Hundred-and-Plantation-Virginia-from-Jamestown-to-Appomattox-by-Clifford-Dowdey.pdf
    • http://loaminoo.linkpc.net/3092094094092093/The-Life-and-Struggles-of-Our-Mother-Walatta-Petros-A-Seventeenth-Century-African-Biography-of-an-Ethiopian-Woman-by-Galawdewos.pdf
    • http://loaminoo.linkpc.net/5091097090098090/New-Netherland-Connections-Intimate-Networks-and-Atlantic-Ties-in-Seventeenth-Century-America-by-Susanah-Shaw-Romney.pdf
    • http://loaminoo.linkpc.net/7092095098094094/Ish-Noo-Ju-Lut-Sche-Or-the-Eagle-of-the-Mohawks-A-Tale-of-the-Seventeenth-Century-Volume-1-of-2-by-John-Linneaus-Edward-Whitridge-Shecut.pdf
    • http://loaminoo.linkpc.net/1095090098092097/Religion-and-the-Decline-of-Magic-Studies-in-Popular-Beliefs-in-Sixteenth-and-Seventeenth-Century-England-by-Keith-Thomas.pdf
    • http://loaminoo.linkpc.net/7092095098095090/Ish-Noo-Ju-Lut-Sche-Or-the-Eagle-of-the-Mohawks-A-Tale-of-the-Seventeenth-Century-Volume-2-of-2-by-John-Linneaus-Edward-Whitridge-Shecut.pdf