Malicious PDF — malware analysis report

Static analysis result for SHA-256 640a9e013b752ab6…

MALICIOUS

PDF

13.9 KB Created: 2019-05-01 20:08:38 +01:00 Authoring application: mPDF 5.7
MD5: ef0f0acbbb65dbcb27a129930f187d2b SHA-1: 4788edf9484c3ab781f2c285d09747fb6732b4b4 SHA-256: 640a9e013b752ab64e0f99fac5829abdc86c102ed2cd3d96196f19ba88c5d74f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by a machine learning classifier and contains a large number of embedded links, many of which point to numeric slugs on the 'loaminoo.linkpc.net' domain. This behavior is indicative of a link farm or SEO manipulation tactic, often used to distribute malicious content or drive traffic to phishing sites. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3099091099091099/Broken-Wings-Dark-Angel-Chronicles-2-by-Melanie-Nilles.pdf
    • http://loaminoo.linkpc.net/4097091096091094/Broken-Wings-Chronicles-of-Brydon-1-by-Lora-Leigh.pdf
    • http://loaminoo.linkpc.net/3097092099097098/Beneath-the-Crashing-Waves-by-Melanie-Nilles.pdf
    • http://loaminoo.linkpc.net/1095096094096096/Fireblood-Legend-of-the-White-Dragon-4-by-Melanie-Nilles.pdf
    • http://loaminoo.linkpc.net/3097093091099091/Soriel-Starfire-Angels-Revelations-1-by-Melanie-Nilles.pdf
    • http://loaminoo.linkpc.net/3097096096095091/The-Fallen-Chronicles-Broken-Angel-by-Amanda-Jones.pdf
    • http://loaminoo.linkpc.net/1097093098097092/Broken-Hearts-Kaleigh-s-Revenge-Broken-Wings-2-by-Sandra-Love.pdf
    • http://loaminoo.linkpc.net/1097093098093098/Broken-Wings-Broken-1-by-Erika-Ashby.pdf
    • http://loaminoo.linkpc.net/2099097092093096/Broken-Broken-Wings-1-by-Sandra-Love.pdf
    • http://loaminoo.linkpc.net/3090098097098095/Broken-Broken-Wings-1-by-Sandra-Love.pdf
    • http://loaminoo.linkpc.net/1092095090099091/Broken-Wings-Broken-3-by-K-S-Ruff.pdf
    • http://loaminoo.linkpc.net/4093096098090092/The-Angel-Chronicles-Vol-2-The-Angel-Chronicles-2-by-Richie-Tankersley-Cusick.pdf
    • http://loaminoo.linkpc.net/4093096098090090/The-Angel-Chronicles-Vol-1-The-Angel-Chronicles-1-by-Nancy-Holder.pdf
    • http://loaminoo.linkpc.net/2094094090097097/Broken-Wings-by-D-G-Torrens.pdf
    • http://loaminoo.linkpc.net/3092095093094091/Broken-Wings-by-Carla-Stewart.pdf
    • http://loaminoo.linkpc.net/4098096099094092/Falling-Girl-With-Broken-Wings-1-by-J-Bennett.pdf
    • http://loaminoo.linkpc.net/3099095094098093/On-Broken-Wings-Wild-Aces-3-by-Chanel-Cleeton.pdf
    • http://loaminoo.linkpc.net/2097093096095092/Beneath-Angel-s-Wings-by-E-Summers.pdf
    • http://loaminoo.linkpc.net/2098097095099/With-Angel-s-Wings-by-Stephanie-A-Collins.pdf
    • http://loaminoo.linkpc.net/5090091099094098/On-Angel-Wings-by-Michael-Morpurgo.pdf