Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b8f205942463b10…

MALICIOUS

PDF

18.6 KB Created: 2019-04-30 06:40:12 +01:00 Authoring application: mPDF 5.7
MD5: 9d01e20d96a098ea485309d637a4cb42 SHA-1: fe8b7d63ab7c4b52aec1bc160a85faf5b42f365f SHA-256: 8b8f205942463b109d1fa42e22ab0b323559c6eb0509dc2af3b61db8e14a879c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. The ML classifier strongly indicates maliciousness. The primary attack pattern appears to be SEO manipulation or hosting malicious content via a large number of links. No scripts were extracted, limiting the analysis of direct payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9981

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/4091096094097098/The-Adventures-of-Gracie-amp-MonkeyBear-Book-1-Summer-by-C-S-O-39-Kelly.pdf
    • http://loaminoo.linkpc.net/2093091094096095/The-Summer-Bride-Chance-Sisters-4-by-Anne-Gracie.pdf
    • http://loaminoo.linkpc.net/6096099091096097/Wide-Open-My-Adventures-in-Polyamory-Open-Marriage-and-Loving-on-My-Own-Terms-by-Gracie-X.pdf
    • http://loaminoo.linkpc.net/2091097098097099/The-Last-Summer-of-the-Camperdowns-by-Elizabeth-Kelly.pdf
    • http://loaminoo.linkpc.net/9098091095099/The-Lost-Summer-of-Louisa-May-Alcott-by-Kelly-O-39-Connor-McNees.pdf
    • http://loaminoo.linkpc.net/7093092090092095/The-Adventures-of-Tom-Sawyer-Annotated-Signet-Edition-The-Adventures-of-Tom-and-Huck-Book-1-by-Mark-Twain.pdf
    • http://loaminoo.linkpc.net/2097099091099098/The-Psi-Chotic-Adventures-of-Drew-Darby-by-Richard-W-Kelly.pdf
    • http://loaminoo.linkpc.net/1091090099091098095/Wild-Together-My-Adventures-with-Loki-the-Wolfdog-by-Kelly-Lund.pdf
    • http://loaminoo.linkpc.net/2098098099097096/Destiny-And-Faith-s-Summer-Adventures-by-Teddy-O-39-Malley.pdf
    • http://loaminoo.linkpc.net/9098099090090097/Terri-s-Wildnerness-Adventures-Hanging-from-a-Tree-Terri-s-Wilderness-Adventures-Book-1-by-Tonya-Swift.pdf
    • http://loaminoo.linkpc.net/4094090098099092/The-Little-Book-of-Insults-by-Rosanna-Kelly.pdf
    • http://loaminoo.linkpc.net/1090093099090099097/Sacrifice-Book-One-of-the-Last-Forever-by-Kelly-Komm.pdf
    • http://loaminoo.linkpc.net/2096098093092099/The-Book-of-Summer-by-Michelle-Gable.pdf
    • http://loaminoo.linkpc.net/1092090099091097/Last-Summer-The-Last-Series-Book-1-by-J-M-Paul.pdf
    • http://loaminoo.linkpc.net/4093092098094/The-Summer-Book-by-Tove-Jansson.pdf
    • http://loaminoo.linkpc.net/4091094092096096/Going-Backwards-The-Baptiste-Family-Book-2-by-Jacki-Kelly.pdf
    • http://loaminoo.linkpc.net/3090092096095094/Always-Remembered-Never-Forgotten-Series-Book-3-by-Kelly-Risser.pdf
    • http://loaminoo.linkpc.net/1090092097093099097/Action-Comics-The-Minecraft-Adventures-of-Steve-and-Alex-The-Abominable-Snowman-Part-2-Minecraft-Steve-and-Alex-Adventures-Book-8-by-Anneline-Kinnear.pdf
    • http://loaminoo.linkpc.net/6092094094092095/Circle-the-Sun-Summer-s-Sol-Book-One-by-Susan-Schroder.pdf
    • http://loaminoo.linkpc.net/3090095099090099/Complete-Book-of-the-Summer-Olympics-by-David-Wallechinsky.pdf