Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2c9fbedc9f010f1…

MALICIOUS

PDF

18.0 KB Created: 2019-04-30 07:55:33 +01:00 Authoring application: mPDF 5.7
MD5: 2073c3014257bcb68e1f8886799178ce SHA-1: 0343f3471b57c22d18c65d078a4684c706081890 SHA-256: b2c9fbedc9f010f1b0faf4cb0e53b699391b6366460fb87c3eedcc82bd9302b6
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDFs hosted on the 'loaminoo.linkpc.net' domain, indicating a link farm strategy. This is supported by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document. The embedded URLs are likely used to distribute malicious content or for SEO manipulation. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/4092090090092/Nathaniel-s-1st-Adventure-Cosmic-Aviators-1-by-G-E-F-Neilson.pdf
    • http://loaminoo.linkpc.net/2090098093098091/Cosmic-Aviators-Cosmic-Aviators-1-by-G-E-F-Neilson.pdf
    • http://loaminoo.linkpc.net/4090097094094093/West-of-Dead-A-Nathaniel-Caine-Adventure-by-Eric-Bahle.pdf
    • http://loaminoo.linkpc.net/8094094099095095/Grinder-s-Keeper-a-Nathaniel-Caine-Adventure-by-Eric-Bahle.pdf
    • http://loaminoo.linkpc.net/8090090090096092/Glory-Duty-and-the-Gold-Dome-Sires-amp-Sons-Adventure-Series-by-T-Nathaniel-Darnell.pdf
    • http://loaminoo.linkpc.net/4094093091097098/Sparks-in-Cosmic-Dust-Cosmic-Frontiers-1-by-Robert-Appleton.pdf
    • http://loaminoo.linkpc.net/4096092098095093/Cosmic-Chaos-Cosmic-Chronicles-2-by-C-L-Roth.pdf
    • http://loaminoo.linkpc.net/3098096090095094/The-Selected-Short-Stories-of-Nathaniel-Hawthorne-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/1091099097098093095/The-Turning-by-Micky-Neilson.pdf
    • http://loaminoo.linkpc.net/1094092091096098/Even-Mississippi-by-Melany-Neilson.pdf
    • http://loaminoo.linkpc.net/1091099097098090093/Diablo-III-Morbed-by-Micky-Neilson.pdf
    • http://loaminoo.linkpc.net/1091099097097099093/Overwatch-6-Destroyer-by-Micky-Neilson.pdf
    • http://loaminoo.linkpc.net/1091099097098090092/The-War-of-the-Shifting-Sands-by-Micky-Neilson.pdf
    • http://loaminoo.linkpc.net/5096097096098097/Nathaniel-Hawthorne-s-The-Scarlet-Letter-by-Nathaniel-Hawthorne.pdf
    • http://loaminoo.linkpc.net/1090096099097094092/Tamora-Pierce---Alanna-The-First-Adventure-Characters-in-Alanna-The-First-Adventure-Places-in-Alanna-The-First-Adventure-Convent-Court-of-the-Rogue-Great-Mother-Goddess-Sponsor-Sweating-Sickness-Training-Master-Trebond-Ysandir-Alanna-of-P-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/5098098091094092/Mind-of-a-Savant-by-Neilson-Voyne-Smith.pdf
    • http://loaminoo.linkpc.net/1091099097097099095/Diablo-III-Heroes-Rise-Darkness-Falls-by-Micky-Neilson.pdf
    • http://loaminoo.linkpc.net/1091097096090093098/President-Down-Troy-Barclay-Amber-Neilson-2-by-Daniel-Adams.pdf
    • http://loaminoo.linkpc.net/1091099097098094095/Lost-and-Found-An-Autobiography-About-Discovering-Family-by-Micky-Neilson.pdf
    • http://loaminoo.linkpc.net/2099093095097090/Let-The-Adventure-Begin-The-Awesome-Adventure-of-Xiapo-Yellip-Zump-1-by-Jacob-Spire.pdf