Malicious PDF — malware analysis report

Static analysis result for SHA-256 291d2b43ae83ca3f…

MALICIOUS

PDF

18.0 KB Created: 2019-05-02 17:27:05 +01:00 Authoring application: mPDF 5.7
MD5: f19153bb9c721c56e9a244c00fdaf724 SHA-1: 9c3babd8ebcbd0022e28a83e853aaa85ae523b45 SHA-256: 291d2b43ae83ca3f66e4c6489683d75aa541ee3f9504030e055de1011409a79f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly flagged this file as malicious. The embedded URLs, while individually marked as benign, collectively form a link farm hosted on loaminoo.linkpc.net, suggesting a potential attempt to drive traffic or distribute further content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9098095094099096/Somnolia-Folge-deinen-Tr-umen-by-Stephanie-Sorhage.pdf
    • http://loaminoo.linkpc.net/1091090094096097095/Nur-In-Deinen-Armen-Die-Cynster-Familie-6-by-Stephanie-Laurens.pdf
    • http://loaminoo.linkpc.net/9098093099091097/Ware-Eine-Einheitsfront-Von-Kpd-Und-SPD-Eine-Alternative-Zur-Tolerierungspolitik-Der-SPD-Gewesen-Wo-Gab-Es-Chancen-in-Folge-Der-Jahrelangen-Auseinanderentwicklung-Wie-Sah-Diese-Entwicklung-Aus-by-Stephanie-G-Rk.pdf
    • http://loaminoo.linkpc.net/1091098097096093091/Kulturgrenzen-in-Postimperialen-R-umen-Bosnien-Und-Westukraine-ALS-Transkulturelle-Regionen-by-Alexander-Kratochvil.pdf
    • http://loaminoo.linkpc.net/5099099096094097/Lebe-deinen-Traum-by-Lucy-Sky.pdf
    • http://loaminoo.linkpc.net/1090099094099094091/Wider-deinen-N-chsten-by-Hans-Montag.pdf
    • http://loaminoo.linkpc.net/1091095097093096094/Das-B-se-in-deinen-Augen-by-Jenny-Blackhurst.pdf
    • http://loaminoo.linkpc.net/1091095097094094092/Sommer-in-deinen-Augen-by-Sara-Belin.pdf
    • http://loaminoo.linkpc.net/1091092091090099091/K-ss-niemals-deinen-Ex-by-Birgit-Kluger.pdf
    • http://loaminoo.linkpc.net/8098095095094093/Das-L-cheln-in-deinen-Augen-by-Julia-Arden.pdf
    • http://loaminoo.linkpc.net/1091095097093096093/Mein-Gl-ck-in-deinen-Augen-by-Cardeno-C-.pdf
    • http://loaminoo.linkpc.net/9096099095098095/Salz-auf-deinen-Lippen-by-Kerry-Greine.pdf
    • http://loaminoo.linkpc.net/9098095094099094/In-Deinen-k-hnsten-Tr-umen-by-Sarah-Sanchez.pdf
    • http://loaminoo.linkpc.net/1091095097093095097/Angst-In-Deinen-Augen-by-Tess-Gerritsen.pdf
    • http://loaminoo.linkpc.net/1091095097094094090/Hungrig-Bin-Ich-Will-Deinen-Mund-Liebessonette-by-Pablo-Neruda.pdf
    • http://loaminoo.linkpc.net/1090091095091090098/Nimm-Deinen-Mut-in-beide-H-nde-Briefe-by-George-Sand.pdf
    • http://loaminoo.linkpc.net/6095095093093091/In-deinen-Augen-The-Wolves-of-Mercy-Falls-3-by-Maggie-Stiefvater.pdf
    • http://loaminoo.linkpc.net/1091095092098093092/Verzaubert-von-deinen-K-ssen-JULIA-1959-by-Tina-Duncan.pdf
    • http://loaminoo.linkpc.net/9091091098096096/Z-rtliche-Versuchung-in-deinen-Armen-Julia-2309-by-Cathy-Williams.pdf
    • http://loaminoo.linkpc.net/9093098092095093/Berauscht-von-deinen-wilden-K-ssen-Baccara-1906-by-Yvonne-Lindsay.pdf