Malicious PDF — malware analysis report

Static analysis result for SHA-256 9db57d8305004b00…

MALICIOUS

PDF

18.9 KB Created: 2019-05-07 03:10:57 +01:00 Authoring application: mPDF 5.7
MD5: fdd2da1699e68d42c7382e442ce80208 SHA-1: a4525bb23c79498c2d8ffe6d38a8272e878c9daa SHA-256: 9db57d8305004b0073e9b7a118b64c017d2d8aab11a969e1415522225281d0a9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, forming a link farm. These links, such as http://loaminoo.linkpc.net/1090096096093098090/P-kudde-av-gr-s-Tales-of-the-Otori-2-by-Lian-Hearn.pdf, likely serve as a lure to download further malicious content or redirect users to phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090096096093098090/P-kudde-av-gr-s-Tales-of-the-Otori-2-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/1090098091096098/The-Tales-of-the-Otori-Trilogy-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/3099096091099/Brilliance-of-the-Moon-Tales-of-the-Otori-3-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/8095090094099/Brilliance-of-the-Moon-Tales-of-the-Otori-3-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/4090098092094/The-Harsh-Cry-of-the-Heron-Tales-of-the-Otori-4-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/4092097096099096/Across-the-Nightingale-Floor-Tales-of-the-Otori-1-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/4098096094097099/Grass-for-His-Pillow-Tales-of-the-Otori-2-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/1095094091093092/Across-the-Nightingale-Floor-Tales-of-the-Otori-1-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/1090096097098097096/-ver-n-ktergalens-golv-Tales-of-the-Otori-1-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/6096097094094094/Grass-for-His-Pillow-Episode-2-The-Way-Through-the-Snow-Tales-of-the-Otori-2-Ep-2-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/6096097094094092/Across-The-Nightingale-Floor-Episode-2-Journey-To-Inuyama-Tales-of-the-Otori-1-Ep-2-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/6096097094094095/Grass-for-His-Pillow-Episode-1-Lord-Fujiwara-s-Treasures-Tales-of-the-Otori-2-Ep-1-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/6096097094098093/Der-Clan-der-Otori-Das-Schwert-in-der-Stille-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/2096093094097094/Emperor-of-the-Eight-Islands-Tale-of-Shikanoko-1-2-by-Lian-Hearn.pdf
    • http://loaminoo.linkpc.net/2094092090091/Lafcadio-Hearn-s-quot-The-Faceless-Ghost-quot-and-Other-Macabre-Tales-from-Japan-A-Graphic-Novel-by-Sean-Michael-Wilson.pdf
    • http://loaminoo.linkpc.net/3094090090095093/Star-Wars-Tales-Omnibus-Tales-from-the-Mos-Eisley-Cantina-Tales-of-the-Bounty-Hunters-and-Tales-from-Jabba-s-Palace-by-Kevin-J-Anderson.pdf
    • http://loaminoo.linkpc.net/6096097094095090/Otori-of-Price-by-Beverly-Farmer.pdf
    • http://loaminoo.linkpc.net/6096097094094098/Knife-in-the-Otori-by-John-Austin.pdf
    • http://loaminoo.linkpc.net/6096097094097093/The-Sorcerer-of-the-Stormed-Otori-by-Darrell-Smith.pdf
    • http://loaminoo.linkpc.net/7096095099092094/Rats-by-Lian-Tanner.pdf
    • http://loaminoo.linkpc.net/6096097094094094/Grass-for-His-Pillow-Episode-2-The-Way-Through-the-Snow