Malicious PDF — malware analysis report

Static analysis result for SHA-256 838333d3406041ce…

MALICIOUS

PDF

16.5 KB Created: 2019-05-03 05:03:47 +01:00 Authoring application: mPDF 5.7
MD5: ce344f8b932ce0f6b4e2b1a4a670d6dc SHA-1: a8b3f590cf460bf901b6d4a0d7187e6c20c8c9cb SHA-256: 838333d3406041cef06bca90bb5c48710f8ce0d78bb66983f992b02ef13d3aba
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the 'loaminoo.linkpc.net' domain. This behaviour is indicative of a link farm or a redirection scheme designed to drive traffic to potentially malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4096094091098/A-Witch-in-Winter-Winter-Trilogy-1-by-Ruth-Warburton.pdf
    • http://loaminoo.linkpc.net/5097090097094/A-Witch-Alone-Winter-Trilogy-3-by-Ruth-Warburton.pdf
    • http://loaminoo.linkpc.net/1090097091097096/Witch-Finder-Witch-Finder-1-by-Ruth-Warburton.pdf
    • http://loaminoo.linkpc.net/1091095092096093/The-Winter-Witch-by-Paula-Brackston.pdf
    • http://loaminoo.linkpc.net/5095096099095090/The-Winter-Witch-by-Paula-Brackston.pdf
    • http://loaminoo.linkpc.net/2093091097091/Wandering-Through-Winter-A-Naturalist-s-Record-of-a-20-000-Mile-Journey-Through-the-North-American-Winter-by-Edwin-Way-Teale.pdf
    • http://loaminoo.linkpc.net/2092090092097096/Winter-s-Scars-The-Forsaken-Winter-s-Saga-5-by-Karen-Luellen.pdf
    • http://loaminoo.linkpc.net/2094096091090099/The-War-Against-Miss-Winter-Rosie-Winter-1-by-Kathryn-Miller-Haines.pdf
    • http://loaminoo.linkpc.net/1095095097090099/Winter-s-Wrath-Sacrifice-Winter-s-Saga-3-by-Karen-Luellen.pdf
    • http://loaminoo.linkpc.net/2096094092091096/Ruth-Bader-Ginsburg-The-Case-of-R-B-G-vs-Inequality-by-Jonah-Winter.pdf
    • http://loaminoo.linkpc.net/9092091099096/The-Road-to-Winter-Winter-1-by-Mark-Smith.pdf
    • http://loaminoo.linkpc.net/1090094092097/Winter-of-the-World-The-Century-Trilogy-2-by-Ken-Follett.pdf
    • http://loaminoo.linkpc.net/1090098090090097091/Rotes-Meer-Der-achte-Fall-f-r-Erik-Winter-Ein-Erik-Winter-Krimi-by-ke-Edwardson.pdf
    • http://loaminoo.linkpc.net/1090098098096092098/Hush-Little-Baby-A-Jefferson-Winter-Thriller-0-6-The-Jefferson-Winter-Chronicles-2-by-James-Carol.pdf
    • http://loaminoo.linkpc.net/4094091099097/Immortal-Fire-Red-Winter-Trilogy-3-by-Annette-Marie.pdf
    • http://loaminoo.linkpc.net/1094097096099090/The-Winter-Door-The-Gateway-Trilogy-2-by-Isobelle-Carmody.pdf
    • http://loaminoo.linkpc.net/1090098093090094/Dark-Winter-The-Wicca-Circle-Dark-Winter-1-by-John-Hennessy.pdf
    • http://loaminoo.linkpc.net/2099091094091093/Winter-Garden-Winter-Garden-2-by-Adele-Ashworth.pdf
    • http://loaminoo.linkpc.net/1097099098097092/The-Winter-People-The-Winter-People-1-by-Rebekah-L-Purdy.pdf
    • http://loaminoo.linkpc.net/8094096094091/Winter-Garden-Winter-Garden-2-by-Adele-Ashworth.pdf