Malicious PDF — malware analysis report

Static analysis result for SHA-256 a97e377a67d4f476…

MALICIOUS

PDF

13.2 KB Created: 2019-05-07 03:19:26 +01:00 Authoring application: mPDF 5.7
MD5: d0c54eef05a89427c39132021caef8e3 SHA-1: b4420d392c7db6abcd629492ce8a0b45a1d4ae1d SHA-256: a97e377a67d4f4764fa9987a09761f54fd3ab5f3330a2d89709e309d581756fd
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links all point to the same domain, loaminoo.linkpc.net, and appear to be designed to direct users to external content. The ML_NYX_PDF_MALICIOUS heuristic also flagged this file as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9006

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.n
    • http://loaminoo.linkpc.net/5093092098097096/Crocodile-s-Sore-Tooth-Crocodile-s-Sore-Tooth-by-Fundisile-Gwazube.pdf
    • http://loaminoo.linkpc.net/3090093092097093/Prince-of-Dorkness-More-Notes-from-a-Totally-Lame-Vampire-Notes-2-by-Tim-Collins.pdf
    • http://loaminoo.linkpc.net/9099099094094096/Notes-from-Hampstead-The-Writer-s-Notes-1954-1971-by-Elias-Canetti.pdf
    • http://loaminoo.linkpc.net/1092095096091098/Notes-on-a-Rebellion-Notes-from-Random-Knight-1-by-Valentina-Hepburn.pdf
    • http://loaminoo.linkpc.net/9094091099091094/Notes-on-a-Rebellion-Notes-from-Random-Knight-1-by-Valentina-Hepburn.pdf
    • http://loaminoo.linkpc.net/8090095092098094/The-Crocodile-by-Vincent-Eri.pdf
    • http://loaminoo.linkpc.net/4096090091093097/Crocodile-Undie-by-A-J-Llewellyn.pdf
    • http://loaminoo.linkpc.net/8090095092098098/The-crocodile-nest-by-Des-Hunt.pdf
    • http://loaminoo.linkpc.net/8090095093094093/Crocodile-by-Mick-Inkpen.pdf
    • http://loaminoo.linkpc.net/8090095093093098/The-Crocodile-Under-the-Bed-by-Judith-Kerr.pdf
    • http://loaminoo.linkpc.net/5094094091092091/F-Scott-Fitzgerald-s-the-Great-Gatsby-Monarch-Notes-by-Monarch-Notes.pdf
    • http://loaminoo.linkpc.net/1090097093094094095/Little-Shoko-and-the-Crocodile-by-Thelma-Sithole.pdf
    • http://loaminoo.linkpc.net/8090095093092099/Daffodil-Crocodile-by-Emily-Jenkins.pdf
    • http://loaminoo.linkpc.net/8090095093091092/The-Crocodile-Fury-by-Beth-Yahp.pdf
    • http://loaminoo.linkpc.net/4099098098096098/Crocodile-Beat-by-Gail-Jorgensen.pdf
    • http://loaminoo.linkpc.net/1092093098093094/The-Enormous-Crocodile-by-Roald-Dahl.pdf
    • http://loaminoo.linkpc.net/8097093096092/The-Enormous-Crocodile-by-Roald-Dahl.pdf
    • http://loaminoo.linkpc.net/1094095095093097/Inside-the-Crocodile-by-Trish-Nicholson.pdf
    • http://loaminoo.linkpc.net/8090095092093090/The-Clumsy-Crocodile-by-Felicity-Everett.pdf
    • http://loaminoo.linkpc.net/8090095093090093/Crocodile-Burning-by-Michael-Williams.pdf