Malicious PDF — malware analysis report

Static analysis result for SHA-256 961162a1fa36ebae…

MALICIOUS

PDF

16.0 KB Created: 2019-04-30 04:27:48 +01:00 Authoring application: mPDF 5.7
MD5: 04479db3b7403620958694fadd8db738 SHA-1: 904dc9be92b02da4343f1242823850fac13db7b9 SHA-256: 961162a1fa36ebae3dc34e5ff23a4969f288fd4c5d05c7a4b5fee999eef8554b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on loaminoo.linkpc.net. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO spam or to lure users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099091099090093/Jackson-s-Track-Memoir-of-a-Dreamtime-Place-by-Daryl-Tonkin.pdf
    • http://loaminoo.linkpc.net/1099097093092/Track-Conditions-A-Memoir-by-Michael-Klein.pdf
    • http://loaminoo.linkpc.net/3092090096096095/A-Place-For-Wolves-by-Kosoko-Jackson.pdf
    • http://loaminoo.linkpc.net/2099090093097091/Between-a-Rock-and-a-Hot-Place-Why-Fifty-Is-Not-the-New-Thirty-by-Tracey-Jackson.pdf
    • http://loaminoo.linkpc.net/1092093098099095/Heart-in-the-Right-Place-A-Memoir-by-Carolyn-Jourdan.pdf
    • http://loaminoo.linkpc.net/2096096097091095/House-Hold-A-Memoir-of-Place-by-Ann-Peters.pdf
    • http://loaminoo.linkpc.net/9091098091098/One-Day-I-Will-Write-About-This-Place-A-Memoir-by-Binyavanga-Wainaina.pdf
    • http://loaminoo.linkpc.net/1092094094090097/Angel-Eyes-A-Collective-Memoir-of-Child-Sexual-Abuse-by-Katandra-Jackson-Nunnally.pdf
    • http://loaminoo.linkpc.net/9091098094093095/Joseph-Roth-s-March-Into-History-From-the-Early-Novels-to-Radetzkymarsch-and-Die-Kapuzinergruft-by-Kati-Tonkin.pdf
    • http://loaminoo.linkpc.net/1096092095096097/The-Diamond-Isle-Dreamtime-3-by-Stan-Nicholls.pdf
    • http://loaminoo.linkpc.net/1099091091092091/The-Dreamtime-Australian-Aboriginal-Myths-by-Charles-P-Mountford.pdf
    • http://loaminoo.linkpc.net/1090098095099097093/Chasing-Dreamtime-A-Sea-Going-Hitchhiker-s-Journey-Through-Memory-and-Myth-by-Neva-Sullaway.pdf
    • http://loaminoo.linkpc.net/2096090097099/Pandemonium-by-Daryl-Gregory.pdf
    • http://loaminoo.linkpc.net/4095097094099096/Getting-Lucky-by-Daryl-Banner.pdf
    • http://loaminoo.linkpc.net/1090094098094095090/Madonna-by-Daryl-Easlea.pdf
    • http://loaminoo.linkpc.net/1092090097093098/Girl-on-the-Run-by-Daryl-Wood-Gerber.pdf
    • http://loaminoo.linkpc.net/1093096095095092/The-Devil-s-Alphabet-by-Daryl-Gregory.pdf
    • http://loaminoo.linkpc.net/5090096097091090/Kappa-Quartet-by-Daryl-Qilin-Yam.pdf
    • http://loaminoo.linkpc.net/2095098091097/We-Are-All-Completely-Fine-by-Daryl-Gregory.pdf
    • http://loaminoo.linkpc.net/3096094096093091/Outlier-Legacy-by-Daryl-Banner.pdf
    • http://loaminoo.linkpc.net/9091098094093095/Joseph-Roth-s-March-Into-History-From-the-Early-Novels