Malicious PDF — malware analysis report

Static analysis result for SHA-256 8896c63f74c35f79…

MALICIOUS

PDF

17.7 KB Created: 2019-05-03 05:07:42 +01:00 Authoring application: mPDF 5.7
MD5: f6c999a207ff97c2ab804b17c201675a SHA-1: 75bbd2eecd1852a40c753e01befac8b16ed3b53a SHA-256: 8896c63f74c35f79d7da65eb49d0c150628abe829fa2b7abfd6b37e25a85af2d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, characteristic of a link farm designed to manipulate search engine results or distribute content. The ML classifier strongly flagged this PDF as malicious. The primary attack pattern involves directing users to a network of potentially malicious or unwanted content via these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.link
    • http://loaminoo.linkpc.net/5093096097098091/Princess-Jellyfish-2-in-1-Omnibus-Volume-7-Princess-Jellyfish-2-in-1-Omnibus-7-by-Akiko-Higashimura.pdf
    • http://loaminoo.linkpc.net/5093096098093093/Princess-Jellyfish-2-in-1-Omnibus-Volume-8-Princess-Jellyfish-2-in-1-Omnibus-8-by-Akiko-Higashimura.pdf
    • http://loaminoo.linkpc.net/4096091098094095/Princess-Jellyfish-2-in-1-Omnibus-Volume-3-Princess-Jellyfish-2-in-1-Omnibus-3-by-Akiko-Higashimura.pdf
    • http://loaminoo.linkpc.net/5093097090090095/Princess-Jellyfish-46-by-Akiko-Higashimura.pdf
    • http://loaminoo.linkpc.net/5093097090091091/Princess-Jellyfish-4-by-Akiko-Higashimura.pdf
    • http://loaminoo.linkpc.net/5093096099094092/Princess-Jellyfish-1-by-Akiko-Higashimura.pdf
    • http://loaminoo.linkpc.net/6090095096096/The-Complete-Princess-Trilogy-Princess-Princess-Sultana-s-Daughters-and-Princess-Sultana-s-Circle-by-Jean-Sasson.pdf
    • http://loaminoo.linkpc.net/5097093097091092/A-Jellyfish-for-Every-Name-by-David-Rawson.pdf
    • http://loaminoo.linkpc.net/5097093097091096/Jellyfish-by-Elaine-Landau.pdf
    • http://loaminoo.linkpc.net/5097093097091099/Swimming-With-The-Jellyfish-by-Vicki-Hastrich.pdf
    • http://loaminoo.linkpc.net/1098092098099/Jellyfish-Inside-Out-by-Michelle-McKenzie.pdf
    • http://loaminoo.linkpc.net/4096098099097093/The-Princess-in-Black-and-the-Perfect-Princess-Party-The-Princess-in-Black-2-by-Shannon-Hale.pdf
    • http://loaminoo.linkpc.net/6099091099/Spineless-The-Science-of-Jellyfish-and-the-Art-of-Growing-a-Backbone-by-Juli-Berwald.pdf
    • http://loaminoo.linkpc.net/5093096098098094/Tokyo-Tarareba-Girls-Vol-1-9-by-Akiko-Higashimura.pdf
    • http://loaminoo.linkpc.net/5093096099093096/Tokyo-Tarareba-Girls-Vol-1-3-by-Akiko-Higashimura.pdf
    • http://loaminoo.linkpc.net/5093096098093098/Tokyo-Tarareba-Girls-Vol-4-by-Akiko-Higashimura.pdf
    • http://loaminoo.linkpc.net/9090094090094/The-Killer-Omnibus-Volume-1-by-Matz.pdf
    • http://loaminoo.linkpc.net/1091098096093093/Lux-Omnibus-Volume-1-by-Jalex-Hansen.pdf
    • http://loaminoo.linkpc.net/3097092098096097/Astro-Boy-Omnibus-Volume-1-by-Osamu-Tezuka.pdf
    • http://loaminoo.linkpc.net/7099099098090090/Criminal-Macabre-Omnibus-Volume-1-by-Ben-Templesmith.pdf