Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd44922c8f06f57a…

MALICIOUS

PDF

23.4 KB Created: 2019-05-01 17:37:42 +01:00 Authoring application: mPDF 5.7
MD5: 3396f35ef5178590b3c42b053da9f16b SHA-1: 1a9fe3f42d28dd0d7a8229e604dede693a02e5b7 SHA-256: fd44922c8f06f57a16690d01375da4dd65c9d31a1c0668d661f1d8f61075eec0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links to external PDF files hosted on the domain 'loaminoo.linkpc.net'. This heuristic firing, combined with the ML classifier's high confidence, suggests a malicious intent, likely SEO poisoning or a link farm designed to distribute malware or lead users to phishing sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7097093097093092/Hegel-or-Spinoza-by-Pierre-Macherey.pdf
    • http://loaminoo.linkpc.net/9099091099096093/Unpublishable-Works-Wolfgang-Borchert-s-Literary-Production-in-Nazi-Germany-by-Erwin-J-Warkentin.pdf
    • http://loaminoo.linkpc.net/7096097091094097/Social-Theory-After-Postmodernism-Law-Production-and-Class-by-Anthony-Woodiwiss.pdf
    • http://loaminoo.linkpc.net/4095090092092096/Literary-Theory-An-Anthology-by-Julie-Rivkin.pdf
    • http://loaminoo.linkpc.net/6095090091095094/Twentieth-Century-Literary-Theory-An-Introductory-Anthology-by-Vassilis-Lambropoulos.pdf
    • http://loaminoo.linkpc.net/1091091096092091093/Literary-Theory-From-Plato-To-Barthes-An-Introductory-History-by-Richard-Harland.pdf
    • http://loaminoo.linkpc.net/1091097098097096093/Reception-Study-From-Literary-Theory-to-Cultural-Studies-by-James-Machor.pdf
    • http://loaminoo.linkpc.net/2094092093093/American-Comics-Literary-Theory-and-Religion-The-Superhero-Afterlife-by-A-David-Lewis.pdf
    • http://loaminoo.linkpc.net/3094096090093095/The-Signifying-Monkey-A-Theory-of-African-American-Literary-Criticism-by-Henry-Louis-Gates-Jr-.pdf
    • http://loaminoo.linkpc.net/3094098098098/The-Signifying-Monkey-A-Theory-of-African-American-Literary-Criticism-by-Henry-Louis-Gates-Jr-.pdf
    • http://loaminoo.linkpc.net/5096098094098095/The-Gender-of-Suicide-Knowledge-Production-Theory-and-Suicidology-Katrina-Jaworski-by-Katrina-Jaworski.pdf
    • http://loaminoo.linkpc.net/8093097092092096/Introduction-to-the-Theory-of-the-Early-Universe-Cosmological-Perturbations-and-Inflationary-Theory-by-Dmitry-S-Gorbunov.pdf
    • http://loaminoo.linkpc.net/1090091090097099093/Ergodic-Theory-With-a-View-Towards-Number-Theory-by-Manfred-Einsiedler.pdf
    • http://loaminoo.linkpc.net/5093097096097095/Pierre-Deux-s-French-Country-by-Pierre-Moulin.pdf
    • http://loaminoo.linkpc.net/3096090096093093/The-Omega-Theory-Final-Theory-2-by-Mark-Alpert.pdf
    • http://loaminoo.linkpc.net/5094093096093093/La-Seduction-Policiere-Signes-de-Croissance-D-Un-Genre-Repute-Mineur-Pierre-Magnan-Daniel-Pennac-Et-Quelques-Autres-by-Pierre-Verdaguer.pdf
    • http://loaminoo.linkpc.net/8090091098092090/Theory-and-Practice-of-Managed-Competition-in-Health-Care-Finance-Lectures-in-Economics-Theory-Institutions-Policy-by-Alain-C-Enthoven.pdf
    • http://loaminoo.linkpc.net/8095090093098090/Moi-Pierre-Seel-d-port-homosexuel-Ecrit-en-collaboration-avec-Jean-Le-Bitoux-by-Pierre-Seel.pdf
    • http://loaminoo.linkpc.net/7097094098091094/Le-Cid-Horace-Cinna-Polyeucte-Martyr-Rodogune-Princesse-des-Parthes-H-raclius-Empereur-d-Orient-Nicom-de-Les-Chefs-d-Oeuvre-de-Pierre-Corneille-by-Pierre-Corneille.pdf
    • http://loaminoo.linkpc.net/8095097097091096/C-est-arriv-un-jour-tome-1-Editions-1---Collection-Pierre-Bellemare-by-Pierre-Bellemare.pdf
    • http://loaminoo.linkpc.net/3094096090093095/The-Signifying-Monkey-A-Theory-of-African-American-Literary-Cr