Malicious PDF — malware analysis report

Static analysis result for SHA-256 a0fe88d844745781…

MALICIOUS

PDF

17.5 KB Created: 2019-05-01 17:14:31 +01:00 Authoring application: mPDF 5.7
MD5: 23100e4c41b134e646ec9b68b28a8d1c SHA-1: 2e2b7a50c817e00be2d50eff4e1fefff93cc818c SHA-256: a0fe88d844745781ac3abb2b034bb8566f40de4441b3ec0a030c6d8f8fca6aaa
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The ML classifier strongly flagged this sample as malicious. The primary attack pattern involves directing users to a link farm hosted at loaminoo.linkpc.net.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097099091097097/Breaking-Free-The-Vampire-Diaries-Revelations-1-by-L-Maci.pdf
    • http://loaminoo.linkpc.net/9090093092097095/The-Vampire-Diaries---Stefan-s-Diaries---Rache-ist-nicht-The-Vampire-Diaries-3-by-L-J-Smith.pdf
    • http://loaminoo.linkpc.net/3094095091092096/Breaking-Free-Breaking-Free-1-by-Cara-Dee.pdf
    • http://loaminoo.linkpc.net/3098096093095/The-Craving-The-Vampire-Diaries-Stefan-s-Diaries-3-by-L-J-Smith.pdf
    • http://loaminoo.linkpc.net/3096095091090/Bloodlust-The-Vampire-Diaries-Stefan-s-Diaries-2-by-L-J-Smith.pdf
    • http://loaminoo.linkpc.net/4097092093097/The-Asylum-The-Vampire-Diaries-Stefan-s-Diaries-5-by-L-J-Smith.pdf
    • http://loaminoo.linkpc.net/8098095099094093/Revelations---The-Deeper-Secrets-of-Vampirism-by-The-Temple-of-the-Vampire.pdf
    • http://loaminoo.linkpc.net/8092097096092094/Breaking-the-Code-Westminster-Diaries-by-Gyles-Brandreth.pdf
    • http://loaminoo.linkpc.net/1090092092091098097/Miriam---Breaking-Free-by-Ken-Rander.pdf
    • http://loaminoo.linkpc.net/3090098094091091/Breaking-Free-Guarded-2-by-Cat-Grant.pdf
    • http://loaminoo.linkpc.net/9095096090090093/Low-Carb-So-Simple---Easy-Everyday-Recipes-with-5-Ingredients-or-Less-Gluten-Free-Sugar-Free-Grain-Free-Sweetener-Free-Wheat-Free-Grain-Free-by-Elviira-Krebber.pdf
    • http://loaminoo.linkpc.net/5098099091090/Breaking-Free-Heartland-3-by-Lauren-Brooke.pdf
    • http://loaminoo.linkpc.net/2095091096092098/Breaking-Free-Masters-of-the-Shadowlands-3-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/8095098093096/Breaking-Free-Masters-of-the-Shadowlands-3-by-Cherise-Sinclair.pdf
    • http://loaminoo.linkpc.net/3091098096096097/Breaking-Free-The-Broken-Hearts-Club-3-by-Michele-Barlow.pdf
    • http://loaminoo.linkpc.net/1091092093097092096/The-Pressure-s-Off-Breaking-Free-from-Rules-and-Performance-by-Larry-Crabb.pdf
    • http://loaminoo.linkpc.net/3096092098098099/Breaking-Free-Discover-the-Victory-of-Total-Surrender-by-Beth-Moore.pdf
    • http://loaminoo.linkpc.net/2097091098097094/Enemies-of-the-Heart-Breaking-Free-from-the-Four-Emotions-That-Control-You-by-Andy-Stanley.pdf
    • http://loaminoo.linkpc.net/2096099095090093/Crazy-Is-My-Superpower-How-I-Triumphed-by-Breaking-Bones-Breaking-Hearts-and-Breaking-the-Rules-by-A-J-Mendez-Brooks.pdf
    • http://loaminoo.linkpc.net/4099094093096099/Women-Afraid-to-Eat-Breaking-Free-in-Todays-Weight-Obsessed-World-by-Frances-M-Berg.pdf
    • http://loaminoo.linkpc.net/9095096090090093/Low-Carb-So-Simple---Easy-Everyday-Recipes-with-5-Ingredients-or-Less-Gluten-Free-Sugar-Free-Grain-Free-Sweetener-Free-Wheat-Free-Gr