Malicious PDF — malware analysis report

Static analysis result for SHA-256 6aabf3f7aea4515d…

MALICIOUS

PDF

16.0 KB Created: 2019-05-07 04:41:57 +01:00 Authoring application: mPDF 5.7
MD5: 44ba2f12134bfc232e0b546ffebeb7eb SHA-1: 9d1f82762dc1937f646552536245e8da83cdee5d SHA-256: 6aabf3f7aea4515d3b94763985c17ffcd715aff43f6a465b3fe484a7d82dac5f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the ML classifier also flagged the document as malicious, the specific intent appears to be directing users to a vast collection of PDF files hosted on loaminoo.linkpc.net. The nature of these links suggests a potential SEO manipulation scheme or a method to distribute further malicious content disguised as legitimate documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2091090095093/The-Christmas-Wedding-Ring-by-Susan-Mallery.pdf
    • http://loaminoo.linkpc.net/1091097097091099097/Herbie-Jones-and-the-Birthday-Showdown-Herbie-Jones-7-by-Suzy-Kline.pdf
    • http://loaminoo.linkpc.net/1091097097092092094/Herbie-Jones-Superhero-Herbie-Jones-8-by-Suzy-Kline.pdf
    • http://loaminoo.linkpc.net/1091097097091094098/Herbie-Jones-Herbie-Jones-1-by-Suzy-Kline.pdf
    • http://loaminoo.linkpc.net/3095097092093095/Only-the-Ring-Finger-Knows-The-Ring-Will-Confess-His-Love-Only-the-Ring-Finger-Knows-4-by-Satoru-Kannagi.pdf
    • http://loaminoo.linkpc.net/3095096095090097/Only-the-Ring-Finger-Knows-The-Ring-Finger-Falls-Silent-Only-the-Ring-Finger-Knows-3-by-Satoru-Kannagi.pdf
    • http://loaminoo.linkpc.net/3092099091099091/The-Ring-of-Five-The-Ring-of-Five-Trilogy-1-by-Eoin-McNamee.pdf
    • http://loaminoo.linkpc.net/1091097097092096098/The-Spy-s-Handbook-by-Herbie-Brennan.pdf
    • http://loaminoo.linkpc.net/1091097097091094099/Herbie-s-Big-Adventure-by-Jennie-Poh.pdf
    • http://loaminoo.linkpc.net/1091097097092093094/Herbie-s-Diner-by-L-Joseph-Shosty.pdf
    • http://loaminoo.linkpc.net/1091096090090093092/Die-nuttigen-Praktikantinnen-in-der-Anstalt-by-Sophie-Herbie.pdf
    • http://loaminoo.linkpc.net/4090094091098099/Seriously-Weird-True-Stories-02-by-Herbie-Brennan.pdf
    • http://loaminoo.linkpc.net/1091097097091099098/Herbie-Archives-Volume-2-by-Shane-O-39-Shea.pdf
    • http://loaminoo.linkpc.net/4095091099098090/The-Collected-Stories-of-Ring-Lardner-by-Ring-Lardner.pdf
    • http://loaminoo.linkpc.net/3093097091093098/Barely-Legal-Herbie-Fisher-1-by-Stuart-Woods.pdf
    • http://loaminoo.linkpc.net/1091097097093092090/The-Herbie-Jones-Readers-Theater-by-Suzy-Kline.pdf
    • http://loaminoo.linkpc.net/8095096095093/The-Purple-Emperor-The-Faerie-Wars-Chronicles-2-by-Herbie-Brennan.pdf
    • http://loaminoo.linkpc.net/1093095099095093/Ruler-of-the-Realm-The-Faerie-Wars-Chronicles-3-by-Herbie-Brennan.pdf
    • http://loaminoo.linkpc.net/1091097097093091094/Amanda-Adams-Loves-Herbie-Hickle-by-Patti-Farmer.pdf
    • http://loaminoo.linkpc.net/1091097097091098099/The-Mystery-of-Bloody-River-Herbie-Fox-Stories-2-by-Steven-Vagovics.pdf