Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e72fd3075e64c65…

MALICIOUS

PDF

13.9 KB Created: 2019-04-30 18:43:11 +01:00 Authoring application: mPDF 5.7
MD5: 1470964719c040a77ebfff0ca4ea9e01 SHA-1: 04886a12bf5c92616111c32b75ecad95c456f45b SHA-256: 1e72fd3075e64c65f868d39faec73c2126881a41cb1094cbeed50e3c585ff285
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a redirection scheme designed to lead users to potentially malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8099091093096095/Gun-Law-of-Phoenix-Cline-by-Terrell-L-Bowers.pdf
    • http://loaminoo.linkpc.net/2099092093096093/Just-Flirt-by-Laura-Bowers.pdf
    • http://loaminoo.linkpc.net/1096094098090090/Hey-Canada-by-Vivien-Bowers.pdf
    • http://loaminoo.linkpc.net/1096093096099095/The-Phoenix-Embryo-Seasons-of-the-Phoenix-1-by-Jeanne-Marcella.pdf
    • http://loaminoo.linkpc.net/3090099098095092/Phoenix-Descending-Curse-of-the-Phoenix-1-by-Dorothy-Dreyer.pdf
    • http://loaminoo.linkpc.net/3097090091093093/Secrets-in-Phoenix-Phoenix-Holt-1-by-Gabriella-Lepore.pdf
    • http://loaminoo.linkpc.net/1090098093090098/The-Birth-of-a-Phoenix-Phoenix-Chronicles-1-by-Candice-Snow.pdf
    • http://loaminoo.linkpc.net/4090093094091092/Search-for-the-Phoenix-Phoenix-Series-Book-2-by-Jim-Proctor.pdf
    • http://loaminoo.linkpc.net/8099091093096097/Patsy-Cline-With-CD-Audio-by-Patsy-Cline.pdf
    • http://loaminoo.linkpc.net/4097096096099/Operation-Redwood-by-S-Terrell-French.pdf
    • http://loaminoo.linkpc.net/4093096094095/Racing-the-Devil-by-Jaden-Terrell.pdf
    • http://loaminoo.linkpc.net/6099094099092099/Riptide-Pride-by-Brandon-Terrell.pdf
    • http://loaminoo.linkpc.net/2098092097092/Living-Together-New-And-Selected-Poems-by-Edgar-Bowers.pdf
    • http://loaminoo.linkpc.net/1096097097090097/Eternity-Fallen-Angel-2-by-Heather-Terrell.pdf
    • http://loaminoo.linkpc.net/7090099090092093/Phoenix-Awakens-The-Phoenix-1-by-Eliza-Nolan.pdf
    • http://loaminoo.linkpc.net/7090099090099091/Red-Phoenix-Burning-Red-Phoenix-2-by-Larry-Bond.pdf
    • http://loaminoo.linkpc.net/4095096090097094/Dark-Phoenix-Phoenix-2-by-Elise-Faber.pdf
    • http://loaminoo.linkpc.net/9099090091098098/Longboat-Blues-Matt-Royal-1-by-H-Terrell-Griffin.pdf
    • http://loaminoo.linkpc.net/1093090095090099/The-Rook-The-Patrick-Bowers-Files-2-by-Steven-James.pdf
    • http://loaminoo.linkpc.net/1093091096095094/The-Queen-Patrick-Bowers-Files-5-by-Steven-James.pdf
    • http://loaminoo.linkpc.net/