Malicious PDF — malware analysis report

Static analysis result for SHA-256 2bd74ffd4d72ed88…

MALICIOUS

PDF

27.8 KB Created: 2019-04-30 18:14:27 +01:00 Authoring application: mPDF 5.7
MD5: d2d9f08f6fe0552a6344a01a88401fff SHA-1: bf5f6eaafa42efbf1874a494e37f353600cbe5a4 SHA-256: 2bd74ffd4d72ed88d413bc093e0f193bc63938f712187aa34d25221d574c9a6e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass external link farm, with 32 links pointing to various book titles hosted on loaminoo.linkpc.net. While the individual linked PDFs are marked as benign, the sheer volume and the nature of the heuristic firing (PDF_SEO_LINK_FARM) suggest a malicious intent to manipulate search engine results or to distribute content through a large number of indirect links. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9908

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5093091099093/Christian-Warrior-Women-A-Guide-to-Taking-Back-Your-Faith-Family-amp-Future-Christian-Warrior-Women-Series-Book-1-by-Lisa-Hawkins.pdf
    • http://loaminoo.linkpc.net/6098096096095094/Fierce-Women-The-Power-of-a-Soft-Warrior-by-Kimberly-Wagner.pdf
    • http://loaminoo.linkpc.net/7090098098092095/The-Christian-Remembrancer-Or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-by-Ambrose-Serle.pdf
    • http://loaminoo.linkpc.net/7090098098091099/The-Christian-Remembrancer-Or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-by-Ambrose-Serle.pdf
    • http://loaminoo.linkpc.net/7090098097099099/The-Christian-Remembrancer-Or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-by-Ambrose-Serle.pdf
    • http://loaminoo.linkpc.net/2093098099098097/Searching-for-the-Amazons-The-Real-Warrior-Women-of-the-Ancient-World-by-John-Man.pdf
    • http://loaminoo.linkpc.net/1099098095093098/The-Claiming-of-Rebellious-Ryssa-Warrior-Women-of-Chrysalis-1-by-Bella-Swann.pdf
    • http://loaminoo.linkpc.net/4097098097096096/Taking-Back-God-American-Women-Rising-Up-for-Religious-Equality-by-Leora-Tanenbaum.pdf
    • http://loaminoo.linkpc.net/2095098090092092/The-Amazons-Lives-and-Legends-of-Warrior-Women-Across-the-Ancient-World-by-Adrienne-Mayor.pdf
    • http://loaminoo.linkpc.net/2096097095091095/The-Amazons-Lives-and-Legends-of-Warrior-Women-Across-the-Ancient-World-by-Adrienne-Mayor.pdf
    • http://loaminoo.linkpc.net/4097090093096099/No-Turning-Back-The-History-of-Feminism-and-the-Future-of-Women-by-Estelle-B-Freedman.pdf
    • http://loaminoo.linkpc.net/8096093099097095/Unnatural-Spiritual-Resiliency-in-Queer-Christian-Women-by-Rachel-Murr.pdf
    • http://loaminoo.linkpc.net/2094094090090095/NOT-A-BOOK-What-the-Bleep-Just-Happened-The-Happy-Warrior-s-Guide-to-the-Great-American-Comeback-by-NOT-A-BOOK.pdf
    • http://loaminoo.linkpc.net/9090099091092/The-Complete-Little-Women-Series-Little-Women-Good-Wives-Little-Men-Jo-s-Boys-The-Beloved-Classics-of-American-Literature-The-coming-of-age-series-experiences-with-her-three-sisters-by-Louisa-May-Alcott.pdf
    • http://loaminoo.linkpc.net/9090092095098092/Dr-Christian-s-Guide-To-Growing-Up-by-Christian-Jessen.pdf
    • http://loaminoo.linkpc.net/3096092097098095/Work-Love-Pray-Practical-Wisdom-for-Professional-Christian-Women-and-Those-Who-Want-to-Understand-Them-by-Diane-Paddison.pdf
    • http://loaminoo.linkpc.net/4094094091097099/The-Dark-Warrior-Series-The-Complete-Collection-Contains-Midnight-s-Master-Midnight-s-Lover-Midnight-s-Seduction-Midnight-s-Warrior-Midnight-s-Kiss-Surrender-novella-Dark-Warriors-by-Donna-Grant.pdf
    • http://loaminoo.linkpc.net/1092092095099095/The-Warrior-of-Clan-Kincaid-Highland-Warrior-3-by-Lily-Blackwood.pdf
    • http://loaminoo.linkpc.net/1098098097099096/Deviant-Warrior-Dark-Warrior-Alliance-3-by-Brenda-Trim.pdf
    • http://loaminoo.linkpc.net/3094092090093099/Wed-to-a-Highland-Warrior-The-Warrior-King-4-by-Donna-Fletcher.pdf
    • http://loaminoo.linkpc.net/7090098098091099/The-Christian-Remembrancer-Or-Short-Reflections-Upon-the-Faith-Life-and-Conduct-of-a-Real-Christian-b