Malicious PDF — malware analysis report

Static analysis result for SHA-256 9db073addff5398e…

MALICIOUS

PDF

14.9 KB Created: 2019-05-01 05:11:37 +01:00 Authoring application: mPDF 5.7
MD5: d5acf7591bc990a8d58910bc68652c33 SHA-1: fdf35ec1ae609926b66e921c415bd756d5b9ec73 SHA-256: 9db073addff5398ec89edc3c365728bcdd20a10b18ae6d4c3a88fb0cd04a59a4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, characteristic of a link farm or SEO poisoning attack. The primary heuristic identified 21 external PDF links, with the dominant host being loaminoo.linkpc.net. While the document body contains obfuscated data, the presence of numerous links suggests an attempt to direct users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2097094090097090/Stranded-Love-by-Massimo-Marino.pdf
    • http://loaminoo.linkpc.net/2096095093091093/Mother-s-Love-by-Massimo-Marino.pdf
    • http://loaminoo.linkpc.net/2096095093092097/Till-Death-Do-Us-Part-by-Massimo-Marino.pdf
    • http://loaminoo.linkpc.net/1095093090093096/Daimones-Daimones-Trilogy-1-by-Massimo-Marino.pdf
    • http://loaminoo.linkpc.net/1097096091092095/Daimones-Daimones-Trilogy-1-by-Massimo-Marino.pdf
    • http://loaminoo.linkpc.net/5090098092099090/Daimones-Daimones-Trilogy-1-by-Massimo-Marino.pdf
    • http://loaminoo.linkpc.net/6093099095096093/THROUGH-THE-EYES-OF-MASSIMO-1939---1945-by-Massimo-Micheli.pdf
    • http://loaminoo.linkpc.net/1090090090096098097/Don-Vito-The-Secret-Life-of-the-Mayor-of-the-Corleones-by-Massimo-Ciancimino-Francesco-La-Licata-by-Massimo-Ciancimino.pdf
    • http://loaminoo.linkpc.net/1093095097099098/Massimo-Bottura-Never-Trust-A-Skinny-Italian-Chef-by-Massimo-Bottura.pdf
    • http://loaminoo.linkpc.net/1094096096097098/I-ll-Love-You-Forever-by-Paula-Altenburg.pdf
    • http://loaminoo.linkpc.net/1094095094090091/First-Love-Now-amp-Forever-1-by-Melissa-Johns.pdf
    • http://loaminoo.linkpc.net/4091094097096095/Love-You-Forever-by-Amelia-Bishop.pdf
    • http://loaminoo.linkpc.net/4091093092096090/Touch-of-Love-Forever-and-Always-0-5-by-E-L-Todd.pdf
    • http://loaminoo.linkpc.net/2093093091091092/Forever-Love-by-Deborah-Armstrong.pdf
    • http://loaminoo.linkpc.net/1091099090092090090/Forever-in-Love-Bis-der-Tod-uns-scheidet-by-Emily-Fox.pdf
    • http://loaminoo.linkpc.net/5090094099091091/Love-After-Marriage-Forever-After-2-by-Mia-Kayla.pdf
    • http://loaminoo.linkpc.net/1093091098092090/The-Last-Boyfriend-Forever-Love-1-by-J-S-Cooper.pdf
    • http://loaminoo.linkpc.net/1091096097090096090/Everlasting-Love-Now-amp-Forever-2-by-Melissa-Johns.pdf
    • http://loaminoo.linkpc.net/7097094093095093/For-Now-and-Forever-The-Inn-at-Sunset-Harbor-1-by-Sophie-Love.pdf
    • http://loaminoo.linkpc.net/2091097091099095/Forever-and-Always-Vampire-Love-Story-3-by-H-T-Night.pdf
    • http://loaminoo.linkpc.net/1090090090096098097/Don-Vito-The-Secret-Life-of-the-Mayor-of-the-Corleones-by-Massimo-Ciancimino-Francesco-La-Licata-by-Massim