Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d3a62694b7da098…

MALICIOUS

PDF

17.7 KB Created: 2019-04-30 03:54:09 +01:00 Authoring application: mPDF 5.7
MD5: 9d4aa2f884a8cc553771153a763e2292 SHA-1: 1501bde738e491f0b372afd5fd40fff90752ab66 SHA-256: 9d3a62694b7da098d60c2553298a830c1878995cfd6002b2944e7a44320d336c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the suspicious domain 'loaminoo.linkpc.net'. This pattern is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9091098094090096/Low-Chicago-Wild-Cards-25-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/2099091096093099/Turn-of-the-Cards-Wild-Cards-12-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/2096095099099092/Wild-Cards-Wild-Cards-1-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/3095090093096092/Wild-Cards-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/2099090097099093/Down-and-Dirty-Wild-Cards-5-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/1090090091090093097/Wild-Cards---Der-Sieg-der-Verlierer-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/3093092092090097/One-Eyed-Jacks-Wild-Cards-8-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/6090091096092/Suicide-Kings-Wild-Cards-20-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/3093092092090098/Dealer-s-Choice-Wild-Cards-11-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/3093091099092099/Double-Solitaire-Wild-Cards-10-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/3093092092093091/George-R-R-Martin-s-Wild-Cards-The-Hard-Call-by-Daniel-Abraham.pdf
    • http://loaminoo.linkpc.net/3093092096092097/George-R-R-Martin-s-Wild-Cards-The-Hard-Call-Part-6-by-Daniel-Abraham.pdf
    • http://loaminoo.linkpc.net/3093092099090098/George-R-R-Martin-s-Wild-Cards-The-Hard-Call-Part-3-by-Daniel-Abraham.pdf
    • http://loaminoo.linkpc.net/3093092092093095/George-R-R-Martin-s-Wild-Cards-The-Hard-Call-Part-1-by-Daniel-Abraham.pdf
    • http://loaminoo.linkpc.net/2097098096094094/The-George-R-R-Martin-Song-Of-Ice-and-Fire-Box-Set-featuring-A-Game-of-Thrones-A-Clash-of-Kings-A-Storm-of-Swords-and-A-Feast-for-Crows-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/3091092092092/Wild-Cards-by-Simone-Elkeles.pdf
    • http://loaminoo.linkpc.net/6092090096098096/The-Gangs-of-Chicago-An-Informal-History-of-the-Chicago-Underworld-by-Herbert-Asbury.pdf
    • http://loaminoo.linkpc.net/9093090092095099/City-of-Chicago-Chicago-O-Hare-International-Airport-Audit-Report-at-December-31-1977-by-Bansley-and-Kiener.pdf
    • http://loaminoo.linkpc.net/4098096097098091/Chicago-War-The-Complete-Series-The-Chicago-War-1-4-by-Bethany-Kris.pdf
    • http://loaminoo.linkpc.net/7090098092095095/Church-Connection-Cards-Connect-with-Visitors-Grow-Your-Church-Pastor-Your-People-Little-Cards-Big-Results-by-Yvon-Prehn.pdf