Malicious PDF — malware analysis report

Static analysis result for SHA-256 a31b45ed5145d54e…

MALICIOUS

PDF

18.2 KB Created: 2019-05-02 18:16:25 +01:00 Authoring application: mPDF 5.7
MD5: 977b69395e330ce0df90b2fa94b6c039 SHA-1: ffbb3ad1cbed101f6f3f2cb11a5d926f2cbfd05a SHA-256: a31b45ed5145d54e5d741d9f887fd9c52115cc3da8bbbb0f6bdf1709d4aa4119
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, forming a link farm. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a mass external link farm. The primary purpose appears to be directing users to a large collection of potentially malicious or unwanted content hosted on loaminoo.linkpc.net.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9931

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2099092090091099/Six-Gun-Snow-White-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/2094097096091/Six-Gun-Snow-White-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/5096092097098098/Under-in-the-Mere-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/4099095092094092/Radiance-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/3093096094093096/The-Refrigerator-Monologues-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/7099095098/Space-Opera-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/7097092094093094/Oracles-A-Pilgrimage-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/4095099095095092/Mouse-Koan-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/2093095091097090/Yume-No-Hon-The-Book-of-Dreams-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/2097094090098096/The-Glass-Town-Game-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/2096091090094/In-the-Night-Garden-The-Orphan-s-Tales-1-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/4097094091094091/In-the-Night-Garden-Orphan-s-Tales-1-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/2091096090098098/This-Is-My-Letter-To-The-World-The-Omikuji-Project-Cycle-One-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/2099090094092091/The-Girl-Who-Fell-Beneath-Fairyland-and-Led-the-Revels-There-Fairyland-2-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/3093092093091098/The-Girl-Who-Fell-Beneath-Fairyland-and-Led-the-Revels-There-Fairyland-2-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/2091094096094098/The-Girl-Who-Circumnavigated-Fairyland-in-a-Ship-of-Her-Own-Making-Fairyland-1-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/1090092097099/The-Girl-Who-Soared-Over-Fairyland-and-Cut-the-Moon-in-Two-Fairyland-3-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/4099096095090090/The-Girl-Who-Soared-Over-Fairyland-and-Cut-the-Moon-in-Two-Fairyland-3-by-Catherynne-M-Valente.pdf
    • http://loaminoo.linkpc.net/4096095092092096/Snow-in-Summer-The-Tale-of-an-American-Snow-White-by-Jane-Yolen.pdf
    • http://loaminoo.linkpc.net/4096097091097/Snow-A-Retelling-of-Snow-White-and-the-Seven-Dwarfs-by-Tracy-Lynn.pdf
    • http://loaminoo.linkpc.net/209109609009