Malicious PDF — malware analysis report

Static analysis result for SHA-256 204cf4c6b63f8109…

MALICIOUS

PDF

16.8 KB Created: 2019-05-02 00:57:18 +01:00 Authoring application: mPDF 5.7
MD5: 2c5b861cd3dbf479afb8f761d37becea SHA-1: cfec4a9369a7a0d103a6d608723a518e3ea83d58 SHA-256: 204cf4c6b63f8109dc2adc9117fa3d796c27fa023322e715ce6021690962a5d6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7093096097094092/Total-Frat-Move-by-W-R-Bolen.pdf
    • http://loaminoo.linkpc.net/1090095090091097095/The-Caro-Kann-Move-by-Move-by-Cyrus-Lakdawala.pdf
    • http://loaminoo.linkpc.net/4097094097099099/Total-New-Beginnings-Total-Freedom-2-by-Ann-M-Pratley.pdf
    • http://loaminoo.linkpc.net/3095095092090093/Every-Frat-Boy-Wants-It-by-Todd-Gregory.pdf
    • http://loaminoo.linkpc.net/7099099093096098/Frat-Boy-s-First-Lust-by-Julianne-Reyer.pdf
    • http://loaminoo.linkpc.net/4090093092091096/Hell-Frat-by-Bruce-Rose.pdf
    • http://loaminoo.linkpc.net/3097091091098094/Frat-Girl-by-Kiley-Roache.pdf
    • http://loaminoo.linkpc.net/1096092093095094/Narcissistic-Lovers-How-to-Cope-Recover-and-Move-On-How-to-Cope-Recover-and-Move-on-by-Cynthia-Zayn.pdf
    • http://loaminoo.linkpc.net/1091090093092094090/Frat-Tales-Kase-University-by-K-Tanae.pdf
    • http://loaminoo.linkpc.net/4098099090091098/With-His-Ring-The-Brides-of-Bath-2-by-Cheryl-Bolen.pdf
    • http://loaminoo.linkpc.net/2090097097094/One-Golden-Ring-Brazen-Brides-2-by-Cheryl-Bolen.pdf
    • http://loaminoo.linkpc.net/4099092098095090/Duchess-By-Mistake-House-of-Haverstock-2-by-Cheryl-Bolen.pdf
    • http://loaminoo.linkpc.net/1094093095091091/Crones-Don-t-Whine-Concentrated-Wisdom-for-Juicy-Women-by-Jean-Shinoda-Bolen.pdf
    • http://loaminoo.linkpc.net/4097098096092097/Urgent-Message-from-Mother-Gather-the-Women-Save-the-World-by-Jean-Shinoda-Bolen.pdf
    • http://loaminoo.linkpc.net/4097098093096093/Millionth-Circle-How-to-Change-Ourselves-and-the-World-The-Essential-Guide-to-Women-s-Circles-by-Jean-Shinoda-Bolen.pdf
    • http://loaminoo.linkpc.net/8094095095098095/A-Clear-and-Present-Danger-Narcissism-in-the-Era-of-President-Trump-Revised-Edition-by-Jean-Shinoda-Bolen.pdf
    • http://loaminoo.linkpc.net/2099099096090091/Trust-Fund-Baby-Frat-Boys-Baby-1-by-Aiden-Bates.pdf
    • http://loaminoo.linkpc.net/3095092096096091/A-Christmas-in-Bath-The-Brides-of-Bath-6-by-Cheryl-Bolen.pdf
    • http://loaminoo.linkpc.net/2097092098092099/A-Christmas-in-Bath-The-Brides-of-Bath-6-by-Cheryl-Bolen.pdf
    • http://loaminoo.linkpc.net/2097099094095096/Police-Don-t-Move-well-sometimes-we-do-by-N-E-Wood.pdf
    • http://loaminoo.linkpc.net/409