Malicious PDF — malware analysis report

Static analysis result for SHA-256 1ba9670ad5bede06…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 02:50:32 +01:00 Authoring application: mPDF 5.7
MD5: c38b82ef540a41f7177def2826fa43ed SHA-1: d0050026a001c8529eee18cb05bbbe7b524422c6 SHA-256: 1ba9670ad5bede06e460da6536a028fc09eff5e6fd1f0981c9453e6b04c6e881
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly flagged this PDF as malicious, and the PDF_SEO_LINK_FARM heuristic confirms the suspicious nature of the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3093092094093/Can-t-Stop-Won-t-Stop-A-History-of-the-Hip-Hop-Generation-by-Jeff-Chang.pdf
    • http://loaminoo.linkpc.net/5096092096097/Teenage-Murderer-Alyssa-Bustamante-True-Crime-Bus-Stop-Reads-29-by-Bus-Stop-Guides.pdf
    • http://loaminoo.linkpc.net/1090094099091093/You-Can-t-Stop-Me-You-Can-t-Stop-Me-1-by-Max-Allan-Collins.pdf
    • http://loaminoo.linkpc.net/9094097094096099/STOP-ARGUING-HOW-TO-STOP-ARGUING-PROTECT-QUALITY-TIME-PREVENT-BICKERING-PRESERVE-LOVE-ENJOY-LIFE-DEALING-WITH-DIFFICULT-TALKS-AND-SITUATIONS-THAT-ARE-COMMON-IN-RELATIONSHIPS-by-C-J-Kruse.pdf
    • http://loaminoo.linkpc.net/5099098094094091/Sexy-Body-Secrets-Lose-Your-Pathetic-Fat-Look-Like-a-Movie-Star-Stop-Your-Health-Problems-Bust-the-Flab-Fat-Loose-the-Spear-Tire-Start-Living-the-Life-You-Deserve-by-Jeff-Sandorf.pdf
    • http://loaminoo.linkpc.net/5099098094093099/Weight-Loss-Secrets-Underground-Should-Be-Illegal-Tactics-and-Unknown-But-Simple-Advice-to-Fast-Weight-Loss-Lose-the-Fat-Gain-Unshakable-Confidence-Put-a-Stop-on-Your-Health-Problems-by-Jeff-Sandorf.pdf
    • http://loaminoo.linkpc.net/7094092099/I-Stop-Somewhere-by-T-E-Carter.pdf
    • http://loaminoo.linkpc.net/1099095099090/One-More-Stop-by-Lois-Walden.pdf
    • http://loaminoo.linkpc.net/1090096092092095/Stop-Me-If-You-ve-Heard-This-One-Before-by-David-Yoo.pdf
    • http://loaminoo.linkpc.net/2092090099098094/Stop-Here-by-Beverly-Gologorsky.pdf
    • http://loaminoo.linkpc.net/2095096092095093/Seduction-Last-Stop-1-5-by-Lou-Harper.pdf
    • http://loaminoo.linkpc.net/7091093090/How-to-Stop-Time-by-Matt-Haig.pdf
    • http://loaminoo.linkpc.net/3096090095094090/Dead-Stop-by-D-Nathan-Hilliard.pdf
    • http://loaminoo.linkpc.net/3092092096096093/Next-Stop-Nina-by-Robin-Raven.pdf
    • http://loaminoo.linkpc.net/4095093090092097/Mummy-Make-It-Stop-by-Louise-Fox.pdf
    • http://loaminoo.linkpc.net/1092094098095090/Until-It-Hurts-to-Stop-by-Jennifer-R-Hubbard.pdf
    • http://loaminoo.linkpc.net/2099093093092097/When-the-Cameras-Stop-Rolling-by-Connie-Cox.pdf
    • http://loaminoo.linkpc.net/4097097096094096/Stop-Time-by-Frank-Conroy.pdf
    • http://loaminoo.linkpc.net/1093098094091095/Time-Must-Have-a-Stop-by-Aldous-Huxley.pdf
    • http://loaminoo.linkpc.net/4094090090090/You-Have-to-Stop-This-Secret-5-by-Pseudonymous-Bosch.pdf
    • http://loaminoo.linkpc.net/5099098094094091/Sexy-Body-Secrets-Lose-Your-Pathet