Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8a20eba2b13f57f…

MALICIOUS

PDF

17.7 KB Created: 2019-05-03 05:05:25 +01:00 Authoring application: mPDF 5.7
MD5: 0fb2b8a1c6696d8e94a3ff505390de5a SHA-1: cc27d4f6c6e6341980a015a3d613fa069abcb89b SHA-256: c8a20eba2b13f57ff2cb936e2dd12762238675136ba32c1c1067c6d02bc6e18b
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the document body is unreadable, the presence of numerous links suggests a distribution or SEO manipulation tactic. The primary IOCs are the external URLs hosted on loaminoo.linkpc.net.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093099096093/Bird-of-Paradise-by-Vicki-Covington.pdf
    • http://loaminoo.linkpc.net/8091093096096/The-Ladies-of-Covington-Send-Their-Love-Ladies-of-Covington-1-by-Joan-Medlicott.pdf
    • http://loaminoo.linkpc.net/2095098092091094/Blessing-the-Hands-That-Feed-Us-What-Eating-Closer-to-Home-Can-Teach-Us-About-Food-Community-and-Our-Place-on-Earth-by-Vicki-Robin.pdf
    • http://loaminoo.linkpc.net/4091097098097091/The-Gathering-Dark-Magic-The-Gathering-Ice-Age-Cycle-1-by-Jeff-Grubb.pdf
    • http://loaminoo.linkpc.net/8096093097096091/Vicki-Sherpa-Una-Maestra-En-Katmandu-by-Vicki-Subirana.pdf
    • http://loaminoo.linkpc.net/1091090097090097095/Ich-h-re-was-die-Seelen-sprechen-Selbst-Skeptiker-verlassen-Vicki-Monroe-in-voller-Gewissheit-Auch-wenn-nicht-erkl-rbar-ist-wie-sie-wissen-kann-was-sie-wei-by-Vicki-Monroe.pdf
    • http://loaminoo.linkpc.net/3095093093096095/Gathering-Water-Gathering-Water-1-by-Regan-Claire.pdf
    • http://loaminoo.linkpc.net/7094094097093092/The-Brigade-by-H-A-Covington.pdf
    • http://loaminoo.linkpc.net/1091093097095/One-Little-Kiss-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/3095099095096091/Get-Lucky-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/8099098098099092/HOME-INVASION-SURVIVAL-Offer-30-solutions-on-how-to-prevent-and-defend-against-home-invasion-by-Confession-of-home-invader-by-Doron-Benbenisty.pdf
    • http://loaminoo.linkpc.net/2091099099091097/Playing-the-Part-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/4097098099092094/Confessions-of-a-Single-Father-by-Jim-Covington.pdf
    • http://loaminoo.linkpc.net/4090096094091090/Rush-The-MacKenzie-Family-10-7-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/2091091095098098/Relentlessly-Reckless-Addicted-to-You-6-by-Lucy-Covington.pdf
    • http://loaminoo.linkpc.net/2091091095097099/Totally-Tormented-Addicted-to-You-5-by-Lucy-Covington.pdf
    • http://loaminoo.linkpc.net/2091091095098095/Beautifully-Broken-Addicted-to-You-2-by-Lucy-Covington.pdf
    • http://loaminoo.linkpc.net/5099091/Return-to-Me-Covington-Cove-1-by-Kelly-Moran.pdf
    • http://loaminoo.linkpc.net/3090090099091099/Secret-Santa-Baby-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/3092097091094091/Her-Secret-Lover-What-Happens-In-Vegas-11-by-Robin-Covington.pdf
    • http://loaminoo.linkpc.net/1091090097090097095/Ich-h-re-was-die-Seelen-sprechen-Selbst-Skeptiker-verlassen-Vicki-Monroe-in-voller-Gewissheit-Auch-wenn-nicht-erkl-rbar-ist-wie-sie-wissen-kann-was-sie-wei-by-Vicki-Monr