Malicious PDF — malware analysis report

Static analysis result for SHA-256 b81dc77f7263c155…

MALICIOUS

PDF

13.9 KB Created: 2019-05-02 22:44:23 +01:00 Authoring application: mPDF 5.7
MD5: b73553e0d0efb74d450d86f88efbded9 SHA-1: 8781b007496122ea9df2b95870f458c3b2606748 SHA-256: b81dc77f7263c155ca65f3d2c52c366b2289c2e1e75bbbcf6435ee74090efd03
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which are disguised as book titles. These links point to external PDF files hosted on loaminoo.linkpc.net. The ML_NYX_PDF_MALICIOUS heuristic also flagged this document with high confidence. The primary attack pattern involves luring users to click these links, likely to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1097093091095096/Between-a-Wolf-and-a-Dog-by-Georgia-Blain.pdf
    • http://loaminoo.linkpc.net/2095096094091091/Darkwater-by-Georgia-Blain.pdf
    • http://loaminoo.linkpc.net/6091091095095096/Snake-in-the-Grass-by-Georgia-Blain.pdf
    • http://loaminoo.linkpc.net/1095097093092096/Births-Deaths-Marriages-by-Georgia-Blain.pdf
    • http://loaminoo.linkpc.net/1098095094097099/Drums-and-Shadows-Survival-Studies-among-the-Georgia-Coastal-Negroes-by-Georgia-Writers-39-Project.pdf
    • http://loaminoo.linkpc.net/9096092091098/Georgia-in-Hawaii-When-Georgia-O-Keeffe-Painted-What-She-Pleased-by-Amy-Novesky.pdf
    • http://loaminoo.linkpc.net/4099096097096093/Georgia-A-Novel-of-Georgia-O-Keeffe-by-Dawn-Tripp.pdf
    • http://loaminoo.linkpc.net/3092096094099095/Georgia-O-Keeffe-One-Hundred-Flowers-by-Georgia-O-39-Keeffe.pdf
    • http://loaminoo.linkpc.net/2091093095094095/Special-A-Vol-10-Special-A-10-by-Maki-Minami.pdf
    • http://loaminoo.linkpc.net/8095090095098098/Riopelle-by-Brad-Blain.pdf
    • http://loaminoo.linkpc.net/6091091093098098/Beneath-a-Blood-Moon-by-R-J-Blain.pdf
    • http://loaminoo.linkpc.net/6091091095097090/I-Love-You-Near-and-Far-by-Marjorie-Blain-Parker.pdf
    • http://loaminoo.linkpc.net/6091091094099094/Blain-s-Woods-by-W-Wesley-Miller.pdf
    • http://loaminoo.linkpc.net/6091091095096090/Tales-of-the-Winter-Wolf-Vol-2-by-R-J-Blain.pdf
    • http://loaminoo.linkpc.net/6091091095093092/Witch-s-Blood-by-William-Blain.pdf
    • http://loaminoo.linkpc.net/6091091095094092/Games-for-All-Occasions-by-Mary-E-Blain.pdf
    • http://loaminoo.linkpc.net/6091091094099098/When-Dads-Don-t-Grow-Up-by-Marjorie-Blain-Parker.pdf
    • http://loaminoo.linkpc.net/6091091094099090/Isaac-the-Pirate-Vol-2---The-Capital-by-Christophe-Blain.pdf
    • http://loaminoo.linkpc.net/6091091095095098/Your-Kind-of-Mommy-by-Marjorie-Blain-Parker.pdf
    • http://loaminoo.linkpc.net/2099095091094095/Playing-with-Fire-A-Magical-Romantic-Comedy-by-R-J-Blain.pdf