Malicious PDF — malware analysis report

Static analysis result for SHA-256 93d98db0385dbd2a…

MALICIOUS

PDF

14.2 KB Created: 2019-05-01 17:57:53 +01:00 Authoring application: mPDF 5.7
MD5: 08643ed34b33f4772cd9b20c0ac4850c SHA-1: 8a5dcfd85b19b62f5175386cdc351c1dfc35ce5d SHA-256: 93d98db0385dbd2aee4df8b0f7f3bedb2c30bbff487816927886fc4dd96836a8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, all pointing to the same domain 'loaminoo.linkpc.net'. While the linked PDFs appear to be book titles, the sheer volume and the ML classifier's high confidence score suggest a malicious intent, likely to distribute malware or engage in phishing. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099093095098098/Stay-Out-of-the-Basement-Goosebumps-2-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/1090098097092090097/Goosebumps-Boxset-6-Goosebumps-Books-21-24-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/2096094098099093/Be-Careful-What-You-Wish-For-Goosebumps-12-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/1090098097092090095/Goosebumps-Movie-Novel-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/7095096091094/Be-Careful-What-You-Wish-For-Goosebumps-12-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/2094095090091098/Don-t-Go-To-Sleep-Goosebumps-54-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/2094091098095092/Bad-Hare-Day-Goosebumps-41-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/1090098097091097092/Cry-of-the-Cat-Goosebumps-Series-2000-1-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/1098090096090092/The-Ghost-Next-Door-Goosebumps-10-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/4091099092093/Welcome-to-Dead-House-Goosebumps-1-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/7097092099091/The-Beast-from-the-East-Goosebumps-43-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/4090094091092092/It-Came-from-Beneath-the-Sink-Goosebumps-30-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/1098091093094097/Egg-Monsters-from-Mars-Goosebumps-42-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/1098091091090099/Welcome-to-Camp-Nightmare-Goosebumps-9-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/2094095090094090/My-Best-Friend-Is-Invisible-Goosebumps-57-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/2095091091090097/The-Werewolf-of-Fever-Swamp-Goosebumps-14-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/2094095090092094/The-Abominable-Snowman-of-Pasadena-Goosebumps-38-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/5098090091095/A-Shocker-on-Shock-Street-Goosebumps-35-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/5090095098098091/Slappy-New-Year-Goosebumps-HorrorLand-18-by-R-L-Stine.pdf
    • http://loaminoo.linkpc.net/1090094093093092/Night-of-the-Living-Dummy-Goosebumps-7-by-R-L-Stine.pdf