Malicious PDF — malware analysis report

Static analysis result for SHA-256 2288993b08888ef7…

MALICIOUS

PDF

17.2 KB Created: 2019-05-05 16:18:03 +01:00 Authoring application: mPDF 5.7
MD5: ad4ca60d2a401d066fbf8d1a1ef9f63f SHA-1: 646175d8b17530ada716bfa23499b0a3acf32339 SHA-256: 2288993b08888ef707c952be96576c6195c0c22311c88befaf57731007372a76
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a PDF SEO link farm heuristic, indicating the document contains a large number of embedded links. These links, such as http://loaminoo.linkpc.net/3098094093096098/Aunt-Dimity-and-the-Buried-Treasure-Aunt-Dimity-Mystery-21-by-Nancy-Atherton.pdf, are likely intended to manipulate search engine rankings or redirect users to malicious websites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3098094093096098/Aunt-Dimity-and-the-Buried-Treasure-Aunt-Dimity-Mystery-21-by-Nancy-Atherton.pdf
    • http://loaminoo.linkpc.net/3096092096091095/Aunt-Dimity-s-Death-Aunt-Dimity-Mystery-1-by-Nancy-Atherton.pdf
    • http://loaminoo.linkpc.net/8097093090092/Aunt-Dimity-Digs-In-Aunt-Dimity-Mystery-4-by-Nancy-Atherton.pdf
    • http://loaminoo.linkpc.net/7097097095096092/Muppet---Illustrated-Characters-Abbot-Alice-Andy-the-Armadillo-Anson-Anderson-Arabs-Ariel-Aunt-Agnes-Snuffleupagus-Aunt-Edna-Aunt-Sue-Baby-Monster-Babyface-Magee-Bean-Bunny-Becca-Bird-Big-Boy-Bigfoot-Billy-Bird-Buddy-Bird-Cabbages-Calvi-by-Source-Wikia.pdf
    • http://loaminoo.linkpc.net/6096099091094091/Aunt-Jo-s-Scrap-Bag-Aunt-Jo-s-Scrap-Bag-1-by-Louisa-May-Alcott.pdf
    • http://loaminoo.linkpc.net/1090091096096090094/Insomnia-and-the-Aunt-by-Tan-Lin.pdf
    • http://loaminoo.linkpc.net/2094092094091090/The-Sex-Life-of-My-Aunt-by-Mavis-Cheek.pdf
    • http://loaminoo.linkpc.net/1090096093090091/Who-Stole-Second-Base-by-Aunt-Eeebs.pdf
    • http://loaminoo.linkpc.net/4099098099099091/Charley-s-Aunt-by-Brandon-Thomas.pdf
    • http://loaminoo.linkpc.net/1099097099096091/The-Aunt-s-Story-by-Patrick-White.pdf
    • http://loaminoo.linkpc.net/5090098093099094/The-Dinosaur-Debut-by-Aunt-Eeebs.pdf
    • http://loaminoo.linkpc.net/1091091097099093/Aunt-Rae-s-Remedies-by-LaRae-Olsen.pdf
    • http://loaminoo.linkpc.net/3099090090095093/Aunt-Celia-by-Jane-Gillespie.pdf
    • http://loaminoo.linkpc.net/1093099095097096/The-Aunt-s-Story-by-Patrick-White.pdf
    • http://loaminoo.linkpc.net/1094093092093/A-Home-with-Aunt-Florry-by-Charlene-J-Talbot.pdf
    • http://loaminoo.linkpc.net/2094092094091094/Aunt-Margaret-s-Lover-by-Mavis-Cheek.pdf
    • http://loaminoo.linkpc.net/1096092099093099/Somebody-Tell-Aunt-Tillie-She-s-Dead-ToadWitch-1-by-Christiana-Miller.pdf
    • http://loaminoo.linkpc.net/8091091096091091/Aunt-Bunny-s-Favorite-Recipes-by-George-Barnard.pdf
    • http://loaminoo.linkpc.net/2098098091094095/Aunt-Jane-of-Kentucky-by-Eliza-Calvert-Hall.pdf
    • http://loaminoo.linkpc.net/9091097095098/All-Aunt-Hagar-s-Children-Stories-by-Edward-P-Jones.pdf
    • http://loaminoo.linkpc.net/4099098099099091/C