Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcb42c01dbc4833c…

MALICIOUS

PDF

23.6 KB Created: 2019-05-02 01:54:12 +01:00 Authoring application: mPDF 5.7
MD5: ca0b9d77554351710d8e6068e28ad03f SHA-1: 20fb063ea939943fc5b2b95efaf457044a01e3ae SHA-256: fcb42c01dbc4833c00aa1d0fd5a7d9781b50363592344de0a109308d9d75ec85
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, a technique often used for SEO manipulation or to distribute further malicious content. The document body contains numerous URLs pointing to the `loaminoo.linkpc.net` domain, suggesting a link farm or redirection mechanism. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092099091090096/-First-Impressions-Are-A-Work-in-Progress-by-porthos.pdf
    • http://loaminoo.linkpc.net/5097099091098092/A-Novel-Idea-a-Work-in-Progress-by-Ruth-DuCharme.pdf
    • http://loaminoo.linkpc.net/6094097090094099/Perfectly-Unfinished-The-Work-in-Progress-Journal-by-Martine-Jolicoeur.pdf
    • http://loaminoo.linkpc.net/1093095096092094/A-Work-in-Progress-Notes-on-Food-Cooking-and-Creativity-by-Rene-Redzepi.pdf
    • http://loaminoo.linkpc.net/8099099094091090/Towards-Better-Regulation-Work-in-Progress-in-Developed-and-Emerging-Markets-Journal-of-Financial-Regulation-and-Compliance-Volume-14-Issue-1-by-Oonagh-McDonald.pdf
    • http://loaminoo.linkpc.net/1091098098096091096/Band-Tumbler-Work-Log-Work-Journal-Work-Diary-Log---131-Pages-8-5-X-11-Inches-by-Key-Work-Logs.pdf
    • http://loaminoo.linkpc.net/9090092091090098/The-Origin-Progress-and-Difficulties-of-the-Achill-Mission-As-Detailed-in-the-Minutes-of-Evidence-Taken-Before-the-Select-Committee-of-the-House-of-Lords-Appointed-to-Inquire-Into-the-Progress-and-Operation-of-the-New-Plan-of-Education-in-Ireland-And-by-Edward-Nangle.pdf
    • http://loaminoo.linkpc.net/9093094090095/Progress-Progress-1-by-Amy-Queau.pdf
    • http://loaminoo.linkpc.net/7094094091098090/A-Theology-Of-Work-Work-And-The-New-Creation-Paternoster-Theological-Monographs-by-Darrell-Cosden.pdf
    • http://loaminoo.linkpc.net/1091090090094091/Women-at-Work-The-Transformation-of-Work-and-Community-in-Lowell-Massachusetts-1826-1860-by-Thomas-Dublin.pdf
    • http://loaminoo.linkpc.net/8092090097095091/Getting-Ahead-of-ADHD-What-Next-Generation-Science-Says-about-Treatments-That-Work-and-How-You-Can-Make-Them-Work-for-Your-Child-by-Joel-T-Nigg.pdf
    • http://loaminoo.linkpc.net/6099096096098098/The-Year-s-Work-In-Critical-And-Cultural-Theory-Volume-15-Covering-Work-Published-In-2005-by-Andrew-Hadfield.pdf
    • http://loaminoo.linkpc.net/6099092096095099/First-Impressions-What-You-Don-t-Know-about-How-Others-See-You-by-Ann-Demarais.pdf
    • http://loaminoo.linkpc.net/6099092095093097/First-Wrong-Impressions-by-K-Ball.pdf
    • http://loaminoo.linkpc.net/4095094099091/Impressions-by-Roger-Cooper.pdf
    • http://loaminoo.linkpc.net/6099092095097099/First-Impressions-by-Ruby-Cruz.pdf
    • http://loaminoo.linkpc.net/3093099093090096/The-Fix-Up-First-Impressions-1-by-Tawna-Fenske.pdf
    • http://loaminoo.linkpc.net/4095097096099092/Impressions-by-Antal-Kovacs.pdf
    • http://loaminoo.linkpc.net/6099092094094096/First-Impressions-by-Jude-Deveraux.pdf
    • http://loaminoo.linkpc.net/4091097098092094/Monet-s-Impressions-by-Metropolitan-Museum-of-Art.pdf
    • http://loaminoo.linkpc.net/1091098098096091096/Band-Tumbler-Work-Log-Work-Journal-Work-Diary-Log---131-Pa