Malicious PDF — malware analysis report

Static analysis result for SHA-256 c31f9b5dc3700680…

MALICIOUS

PDF

16.0 KB Created: 2019-04-30 02:46:31 +01:00 Authoring application: mPDF 5.7
MD5: 9ea4c6d30bbdcdab7d1d4c85826db798 SHA-1: 2bc3e8b674d081e6e00efde77287ce73839da491 SHA-256: c31f9b5dc37006800e69c1f4844a8d37f91f59ff355f8c3273a122999f995caf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a link farm hosted on a dynamic DNS domain, likely to distribute further malware or engage in phishing. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2094092097096096/Three-Dates-Paths-to-Love-2-by-Grahame-Claire.pdf
    • http://loaminoo.linkpc.net/3099092097090092/52-Dates-for-Writers---Ride-a-Tandem-Assume-an-Alias-and-50-Other-Ways-to-Improve-Your-Novel-Draft-by-Claire-Wingfield.pdf
    • http://loaminoo.linkpc.net/2098090096095094/Dates-Double-Dates-and-Big-Big-Trouble-Ally-s-World-2-by-Karen-McCombie.pdf
    • http://loaminoo.linkpc.net/5090090090096095/Mates-Dates-and-Sleepover-Secrets-Mates-Dates-4-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/1098091090099096/Mates-Dates-and-Inflatable-Bras-Mates-Dates-1-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/1098091092098090/Mates-Dates-and-Sequin-Smiles-Mates-Dates-7-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/2098090094099096/Mates-Dates-and-Chocolate-Cheats-Mates-Dates-10-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/1098091090095093/Mates-Dates-and-Sizzling-Summers-Mates-Dates-12-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/5090091091094093/Mates-Dates-and-Diamond-Destiny-Mates-Dates-11-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/1098091092096091/Mates-Dates-and-Tempting-Trouble-Mates-Dates-8-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/5096093093098/Paths-of-Darkness-Collector-s-Edition-Forgotten-Realms-Paths-of-Darkness-1-4-by-R-A-Salvatore.pdf
    • http://loaminoo.linkpc.net/1091096091096096096/It-s-Not-Love-by-Claire-Davon.pdf
    • http://loaminoo.linkpc.net/2090092092098092/Tracks-To-Love-by-Abbie-St-Claire.pdf
    • http://loaminoo.linkpc.net/1092092092090094/Let-s-Talk-About-Love-by-Claire-Kann.pdf
    • http://loaminoo.linkpc.net/1090092090093092096/Lilli-in-Love-by-Claire-Singer.pdf
    • http://loaminoo.linkpc.net/3099094096094092/Love-is-a-Thief-by-Claire-Garber.pdf
    • http://loaminoo.linkpc.net/3091091097099099/Dinosaurs-Love-Underpants-by-Claire-Freedman.pdf
    • http://loaminoo.linkpc.net/2092091099095099/Love-is-a-Four-Letter-Word-by-Claire-Calman.pdf
    • http://loaminoo.linkpc.net/2099099099091090/Love-Before-Dawn-Kindred-1-by-Claire-Cullen.pdf
    • http://loaminoo.linkpc.net/3097098093091096/The-Alpha-s-Love-Lost-Omegas-4-by-Claire-Cullen.pdf
    • http://loaminoo.linkpc.net/509009109109