Malicious PDF — malware analysis report

Static analysis result for SHA-256 a247be959b039089…

MALICIOUS

PDF

20.0 KB Created: 2019-04-30 02:05:09 +01:00 Authoring application: mPDF 5.7
MD5: 1878b80712ce491fe549d930f12df5fd SHA-1: 9f5b25750b7b9d231ca9ba5842ff20f60bcf20dd SHA-256: a247be959b039089996c584b9e0bf5f5acf626568ecc29cbc2ef0c964aff805c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links predominantly point to the same domain, loaminoo.linkpc.net, and appear to be designed to direct users to various book titles, likely as a lure. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9942

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096097093095/City-of-Fallen-Angels-The-Mortal-Instruments-4-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/3097093096091091/City-of-Fallen-Angels-The-Mortal-Instruments-4-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/3097096090091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/4098093094096091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/3092095090090/The-Mortal-Instruments-Boxed-Set-City-of-Bones-City-of-Ashes-City-of-Glass-The-Mortal-Instruments-1-3-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/5099093090091093/City-of-Bones-The-Mortal-Instruments-1-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/2097097092093098/City-of-Glass-The-Mortal-Instruments-3-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/3093090090092096/The-Mortal-Instruments-City-of-Bones-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/4092098098096099/City-of-Ashes-The-Mortal-Instruments-2-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/2096097092092/City-of-Bones-The-Mortal-Instruments-1-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/5098091099095/City-of-Bones-The-Mortal-Instruments-1-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/6096094091097095/City-of-Heavenly-Fire-The-Mortal-Instruments-6-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/4098095099091093/City-of-Bones-Shadowhunters-The-Mortal-Instruments-1-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/3099099094090/City-of-Heavenly-Fire-The-Mortal-Instruments-6-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/2098099097090/City-of-Fallen-Angels-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/5092094096099098/The-Mortal-Instruments---tome-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/5092094097090094/The-Mortal-Instruments-Les-origines-tome-3-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/6093092093097093/Clockwork-Princess-The-Mortal-Instruments-Prequel-Volume-3-of-The-Infernal-Devices-Manga-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/6093092093092095/Clockwork-Angel-The-Mortal-Instruments-Prequel-Volume-1-of-The-Infernal-Devices-Manga-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/6093092093092090/The-Mortal-Instruments-Companion-City-of-Bones-Shadowhunters-and-the-Sight-The-Unauthorized-Guide-by-Lois-H-Gresh.pdf
    • http://loaminoo.linkpc.net/3092095090090/The-Mortal-Instruments-Boxed-Set-City-of-Bones-City-of-Ashes-City-of-Glass-The-Mortal-Ins