Malicious PDF — malware analysis report

Static analysis result for SHA-256 82430bb4dd65f265…

MALICIOUS

PDF

21.0 KB Created: 2019-04-30 03:16:12 +01:00 Authoring application: mPDF 5.7
MD5: f305660e30fea8231e7d12d6b51493e8 SHA-1: a6e6b6096adc578a3f6069aebffa1e5d9ea01466 SHA-256: 82430bb4dd65f265e684ec3c97f11b8d78d8c5e200b995e00252a83df8c6bc6e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, identified as a link farm. These links point to various PDF files hosted on loaminoo.linkpc.net. The primary purpose appears to be directing users to external content, potentially as a method of traffic distribution or to host malicious payloads disguised as legitimate documents. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9939

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098098094091098/Japanese-Gothic-Tales-by-Ky-ka-Izumi.pdf
    • http://loaminoo.linkpc.net/7094095099095/In-Light-of-Shadows-More-Gothic-Tales-by-Izumi-Kyoka-by-Ky-ka-Izumi.pdf
    • http://loaminoo.linkpc.net/3098098095093096/Tales-of-Moonlight-and-Rain-Japanese-Gothic-Tales-by-Ueda-Akinari.pdf
    • http://loaminoo.linkpc.net/1090096090097099/Gothic-Ten-Original-Dark-Tales-by-Deborah-Noyes.pdf
    • http://loaminoo.linkpc.net/2098098094091093/Late-Victorian-Gothic-Tales-by-Roger-Luckhurst.pdf
    • http://loaminoo.linkpc.net/7098091097090098/Japanese-Fairy-Tales-by-Yei-Theodora-Ozaki.pdf
    • http://loaminoo.linkpc.net/1090095094092091090/This-photobook-made-by-HIROSHIMA-who-is-altanative-writer-contains-bust-and-hip-of-japanese-cute-girl-paparazzi-of-japanese-amateure-by-king-of-japanese-paparazzi.pdf
    • http://loaminoo.linkpc.net/1090095094092092090/Hiroko-Kumada-is-look-like-a-japanese-famous-idol-and-she-was-massaged-with-electric-vibration-paparazzi-of-japanese-amateure-by-king-of-japanese-paparazzi.pdf
    • http://loaminoo.linkpc.net/6092095095098098/Japanese-Folk-Stories-and-Fairy-Tales-by-Mary-F-Nixon-Roulet.pdf
    • http://loaminoo.linkpc.net/6096093092099093/Bento-Japanese-food-Typical-japanese-box-for-lunch-Japanese-cooking-and-japanese-food-by-Hitomi-nakamura-Book-2-by-Hitomi-Nakamura.pdf
    • http://loaminoo.linkpc.net/1092095099092094/Florida-Gothic-The-quot-Gothic-quot-Series-Book-1-by-Mitzi-Szereto.pdf
    • http://loaminoo.linkpc.net/1091093092094091094/The-47-Ronin-Japanese-Tales-of-Vampires-Ghosts-and-Renegade-Samurai-by-Algernon-Bertram-Freeman-Mitford.pdf
    • http://loaminoo.linkpc.net/8090097096090091/Midwestern-Gothic-Summer-2013---Issue-10-by-Midwestern-Gothic.pdf
    • http://loaminoo.linkpc.net/3091090091097098/Japanese-Cooking-Made-Simple-A-Japanese-Cookbook-with-Authentic-Recipes-for-Ramen-Bento-Sushi-amp-More-by-Salinas-Press.pdf
    • http://loaminoo.linkpc.net/3094090090095093/Star-Wars-Tales-Omnibus-Tales-from-the-Mos-Eisley-Cantina-Tales-of-the-Bounty-Hunters-and-Tales-from-Jabba-s-Palace-by-Kevin-J-Anderson.pdf
    • http://loaminoo.linkpc.net/2098090092093090/Everyone-s-Getting-Married-Vol-1-by-Izumi-Miyazono.pdf
    • http://loaminoo.linkpc.net/6091093097091094/Hikari-no-densetsu-Tome-4-by-Izumi-As-.pdf
    • http://loaminoo.linkpc.net/7097091094090099/La-Fleur-Mill-naire-Vol-13-by-Kaneyoshi-Izumi.pdf
    • http://loaminoo.linkpc.net/9099099096093096/Nadja-of-Tomorrow-by-Toudou-Izumi.pdf
    • http://loaminoo.linkpc.net/1096097099097094/Oresama-Teacher-Vol-1-by-Izumi-Tsubaki.pdf