Malicious PDF — malware analysis report

Static analysis result for SHA-256 5db1113f1fc25c06…

MALICIOUS

PDF

17.1 KB Created: 2019-05-01 06:10:12 +01:00 Authoring application: mPDF 5.7
MD5: a4d671dbaa26aa98b39d1a24df9e06b7 SHA-1: 28bfb575efa1258d1d6a2c3280f1d2673d797908 SHA-256: 5db1113f1fc25c06971017f8719a0db02cae4b4994de22d9a4a1d6900b959235
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by multiple heuristics, including a critical finding for a link farm containing numerous external links. The embedded links, such as http://loaminoo.linkpc.net/2090097096099093/Werewolf-in-the-North-Woods-Wild-About-You-2-by-Vicki-Lewis-Thompson.pdf, suggest a malicious intent to redirect users to potentially harmful content or for SEO manipulation. No scripts were extracted, but the structure indicates a dropper or downloader functionality.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-7202421-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7202421-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090097096099093/Werewolf-in-the-North-Woods-Wild-About-You-2-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/2090097096098097/Werewolf-in-Alaska-Wild-About-You-5-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/2090097096099098/Werewolf-in-Denver-Wild-About-You-4-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/2097098094093097/Werewolf-in-Greenwich-Village-Wild-About-You-Novella-1-5-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/1099098091098093/Nerd-Gone-Wild-Nerds-3-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/9091091098099/Butterflies-In-Sun-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/4093093095092096/The-Perfect-Man-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/1099098091097099/Gone-With-the-Nerd-Nerds-4-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/1092094099096/Pure-Temptation-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/2092095091091093/Rescuing-Christmas-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/1092099096094/It-Happened-One-Weekend-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/3090090098095094/Claimed-Sons-of-Chance-3-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/4099090098092097/Better-Naughty-Than-Nice-No-Mistletoe-Required-Her-Secret-Santa-Snug-in-His-Bed-Harlequin-Blaze-507-by-Vicki-Lewis-Thompson.pdf
    • http://loaminoo.linkpc.net/1092098091090096/Confessions-of-a-Werewolf-Supermodel-by-Ronda-Thompson.pdf
    • http://loaminoo.linkpc.net/1099094093095093/The-Woods-of-North-San-Juan-by-T-E-Fromhold.pdf
    • http://loaminoo.linkpc.net/2095099097092094/Silver-White-The-Great-North-Woods-Pack-1-by-Shawn-Underhill.pdf
    • http://loaminoo.linkpc.net/2092092099094/Invasion-of-the-Bible-Thumpers-Tales-of-the-North-Woods-and-Other-Places-by-Skookum-Maguire.pdf
    • http://loaminoo.linkpc.net/3094090098096094/What-Should-a-Clever-Moose-Eat-Natural-History-Ecology-and-the-North-Woods-by-John-Pastor.pdf
    • http://loaminoo.linkpc.net/7090091098091/Wild-Animals-I-Have-Known-by-Ernest-Thompson-Seton.pdf
    • http://loaminoo.linkpc.net/1092098097095090/Wild-Blood-Switchers-3-by-Kate-Thompson.pdf