Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d37972718116fd9…

MALICIOUS

PDF

14.8 KB Created: 2019-05-07 09:14:13 +01:00 Authoring application: mPDF 5.7
MD5: f276fdf3fff6318d152d00f9691c3819 SHA-1: e08e4755e557e6ad448602e074e048727f8b0656 SHA-256: 9d37972718116fd9b042f4fdd009664116f06f3c58f5f07e479ef4f9a1d774ac
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links, indicating a link farm or redirection scheme. The heuristic PDF_SEO_LINK_FARM specifically identified this behavior, pointing to a malicious intent to drive traffic to external sites. While no scripts were extracted, the sheer volume of links suggests a coordinated effort to lure users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092095090095094/A-Very-Gothic-Christmas-Feehan-Christmas-Stories-1-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/2097090095095097/Christine-Feehan-Box-Set-includes-Drake-Sisters-3-Dark-Saga-10-GhostWalkers-1-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/1090095091098099/A-Christine-Feehan-Holiday-Treasury-Drake-Sisters-2-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/2099096099094093/Dark-Prince-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/3090092097095090/Dark-Desire-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/9090097096090090/W-chterin-der-Erde-Sea-Have-4-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/2098094099093091/Fever-Leopard-People-0-5-1-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/4093091093098099/Predatory-Game-GhostWalkers-6-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/2099093097097096/Judgment-Road-Torpedo-Ink-1-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/1098096097090090/Dark-Magic-Carpathians-4-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/1093094090097099/Samurai-Game-Ghostwalkers-10-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/2090090092096093/Dark-Prince-Carpathians-1-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/1098096097095099/Dark-Desire-Carpathians-2-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/4093091093098098/Deadly-Game-Ghostwalkers-5-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/4096094090098098/Turbulent-Sea-Drake-Sisters-6-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/1094096/Viper-Game-GhostWalkers-11-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/4091091096095091/Conspiracy-Game-GhostWalkers-4-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/4099092098/Power-Game-GhostWalkers-13-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/7097094091/Covert-Game-GhostWalkers-14-by-Christine-Feehan.pdf
    • http://loaminoo.linkpc.net/2094099094098097/Rocky-Mountain-Miracle-by-Christine-Feehan.pdf