Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d2b16a70aa23834…

MALICIOUS

PDF

19.5 KB Created: 2019-05-02 01:19:50 +01:00 Authoring application: mPDF 5.7
MD5: d5aa07ea2b2d14fd39cbd730c723179c SHA-1: c57ca77f4fa8e16b87342280da4d2b7bdeeaf9a2 SHA-256: 9d2b16a70aa238348cfdbfa53a210f9a4f57ebce865cc219691d91e8e9e4f48e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9912

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093098092092091/Birth-The-Surprising-History-of-How-We-Are-Born-by-Tina-Cassidy.pdf
    • http://loaminoo.linkpc.net/2096095097097091/Hidden-Christmas-The-Surprising-Truth-Behind-the-Birth-of-Christ-by-Timothy-J-Keller.pdf
    • http://loaminoo.linkpc.net/1094092097096096/False-Economy-A-Surprising-Economic-History-of-the-World-by-Alan-Beattie.pdf
    • http://loaminoo.linkpc.net/5091099091096/The-Tale-of-the-Dueling-Neurosurgeons-And-Other-True-Stories-of-Trauma-Madness-Affliction-and-Recovery-That-Reveal-the-Surprising-History-of-the-Human-Brain-by-Sam-Kean.pdf
    • http://loaminoo.linkpc.net/5091094094094096/A-History-of-the-Mind-Evolution-and-the-Birth-of-Consciousness-by-Nicholas-Humphrey.pdf
    • http://loaminoo.linkpc.net/8095099091095091/Taking-Precautions-An-Intimate-History-of-Birth-Control-by-Shyama-Perera.pdf
    • http://loaminoo.linkpc.net/7099099094094098/Born-in-the-Country-A-History-of-Rural-America-by-David-B-Danbom.pdf
    • http://loaminoo.linkpc.net/4096097099091/America-Is-Born-A-History-for-Peter-by-Gerald-White-Johnson.pdf
    • http://loaminoo.linkpc.net/7097092096096091/The-Fateful-History-of-Fannie-Mae-New-Deal-Birth-to-Mortgage-Crisis-Fall-by-James-R-Hagerty.pdf
    • http://loaminoo.linkpc.net/7093090095092096/The-History-of-Saturday-Night-Live-2005-2010-Starring-Tina-Fey-Andy-Samberg-and-Kenan-Thompson-by-Jenny-Reese.pdf
    • http://loaminoo.linkpc.net/2099090096093098/Cassidy-Jones-and-the-Secret-Formula-Cassidy-Jones-Adventures-1-by-Elise-Stokes.pdf
    • http://loaminoo.linkpc.net/6093091092091095/Cassidy-Jones-and-the-Seventh-Attendant-Cassidy-Jones-Adventures-3-by-Elise-Stokes.pdf
    • http://loaminoo.linkpc.net/2099090096093099/Cassidy-Jones-and-Vulcan-s-Gift-Cassidy-Jones-Adventures-2-by-Elise-Stokes.pdf
    • http://loaminoo.linkpc.net/5094092097098/Cassidy-Jones-and-Vulcan-s-Gift-Cassidy-Jones-Adventures-2-by-Elise-Stokes.pdf
    • http://loaminoo.linkpc.net/1090095098097090/Cassidy-Jones-and-the-Secret-Formula-Cassidy-Jones-Adventures-1-by-Elise-Stokes.pdf
    • http://loaminoo.linkpc.net/1090095091095097091/Raising-Multiple-Birth-Children-A-Parent-s-Survival-Guide-Birth-Age-3-by-William-Laut.pdf
    • http://loaminoo.linkpc.net/8091093095097091/The-Birth-Center-An-Approach-to-the-Birth-Experience-by-Salee-Berman.pdf
    • http://loaminoo.linkpc.net/8091093095096099/The-birth-center-An-approach-to-the-birth-experience-by-Salee-Berman.pdf
    • http://loaminoo.linkpc.net/1091093097099099098/The-Birth-of-Motocross-An-Illustrated-History-of-the-Early-Years-of-America-s-1-Dirt-Sport---The-Tracks---The-Riders---The-Machines-by-Robert-Schleichert.pdf
    • http://loaminoo.linkpc.net/3093092099090091/Cassidy-Jones-and-the-Luminous-Cassidy-Jones-Adventures-4-by-Elise-Stokes.pdf
    • http://loaminoo.linkpc.net/7097092096096091/The-Fateful-Histo