Malicious PDF — malware analysis report

Static analysis result for SHA-256 228bc739c9ded17e…

MALICIOUS

PDF

14.5 KB Created: 2019-04-30 11:19:43 +01:00 Authoring application: mPDF 5.7
MD5: a7afb238a01f3ad7d616f2473d39e297 SHA-1: 69b393317331b3f5aa75c628b25671c021600194 SHA-256: 228bc739c9ded17ec7fdfece479331ce00097d9aadbc013912087b178698e28f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, hosted on the domain loaminoo.linkpc.net. This heuristic firing suggests a link farm or a method to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090099097091095/Turn-to-Me-The-Thin-Blue-Thread-2-by-Kaitlyn-Stone.pdf
    • http://loaminoo.linkpc.net/1091092090094091/Gates-of-Thread-and-Stone-Gates-of-Thread-and-Stone-1-by-Lori-M-Lee.pdf
    • http://loaminoo.linkpc.net/1099094096094096/The-Infinite-Gates-of-Thread-and-Stone-2-by-Lori-M-Lee.pdf
    • http://loaminoo.linkpc.net/3096096097091093/A-Spool-of-Blue-Thread-by-Anne-Tyler.pdf
    • http://loaminoo.linkpc.net/2097092092093090/A-Spool-of-Blue-Thread-by-Anne-Tyler.pdf
    • http://loaminoo.linkpc.net/2094097093098095/A-Spool-of-Blue-Thread-by-Anne-Tyler.pdf
    • http://loaminoo.linkpc.net/1097093094090098/A-Spool-of-Blue-Thread-by-Anne-Tyler.pdf
    • http://loaminoo.linkpc.net/3091097094097/A-Spool-of-Blue-Thread-by-Anne-Tyler.pdf
    • http://loaminoo.linkpc.net/3099093098097095/Turn-to-Stone-Jonathan-Stride-5-6-by-Brian-Freeman.pdf
    • http://loaminoo.linkpc.net/1090099096094090097/Biker-s-Betrayal-Blue-Mustangs-MC-3-by-Emily-Stone.pdf
    • http://loaminoo.linkpc.net/7096092092095/Sapphire-Blue-Precious-Stone-Trilogy-2-by-Kerstin-Gier.pdf
    • http://loaminoo.linkpc.net/5092094093099091/On-Thin-Ice-2-On-Thin-Ice-2-by-Victoria-Villeneuve.pdf
    • http://loaminoo.linkpc.net/8091096098098/Turn-Turn-verse-1-by-Sara-39-s-Girl.pdf
    • http://loaminoo.linkpc.net/2095090095095099/Thin-Love-Thin-Love-1-by-Eden-Butler.pdf
    • http://loaminoo.linkpc.net/2096097099091091/The-Last-Thread-by-Ray-Britain.pdf
    • http://loaminoo.linkpc.net/5096094090099098/Murder-Along-the-Blue-Ridge-A-Rachel-Christie-Mystery-6-Rachel-Christie-Mystery-Series-by-Sabena-Stone.pdf
    • http://loaminoo.linkpc.net/4094094093091091/The-Gate-by-Kaitlyn-O-39-Connor.pdf
    • http://loaminoo.linkpc.net/2091099099091092/Tension-By-a-Thread-2-by-R-L-Griffin.pdf
    • http://loaminoo.linkpc.net/5091096094094/The-Red-Thread-by-Roderick-Townley.pdf
    • http://loaminoo.linkpc.net/4096092094094090/The-Hidden-Thread-by-Liz-Trenow.pdf
    • http://loaminoo.linkpc.net/2095090095095099/Thin-Love-Thin-Love-1-by-Eden-B