Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb9dbf110eb97da3…

MALICIOUS

PDF

15.6 KB Created: 2019-05-07 04:13:25 +01:00 Authoring application: mPDF 5.7
MD5: a4c650718e0e0e9cb09bed4546f7e816 SHA-1: 9541aeb129186e6897a5bb4fd9734ada87da689b SHA-256: cb9dbf110eb97da3202153dca1956f218800717fd64b5e3eb6e055250bc4de96
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection scheme. The ML classifier also flagged this PDF as malicious with high confidence. The embedded links, such as http://loaminoo.linkpc.net/1092096097091098/Orlean-Puckett-The-Life-of-a-Mountain-Midwife-by-Karen-Cecil-Smith.pdf, are likely used to direct users to malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1092096097091098/Orlean-Puckett-The-Life-of-a-Mountain-Midwife-by-Karen-Cecil-Smith.pdf
    • http://loaminoo.linkpc.net/1091098094094099/Pillow-of-Thorns-by-Karen-Cecil-Smith.pdf
    • http://loaminoo.linkpc.net/8092097090097/Rin-Tin-Tin-The-Life-and-the-Legend-by-Susan-Orlean.pdf
    • http://loaminoo.linkpc.net/1090094092099093/The-Midwife-s-Apprentice-by-Karen-Cushman.pdf
    • http://loaminoo.linkpc.net/4090090095096093/The-Great-Hunger-Ireland-1845-1849-by-Cecil-Woodham-Smith.pdf
    • http://loaminoo.linkpc.net/1093092097099097/The-Reason-Why-The-Story-of-the-Fatal-Charge-of-the-Light-Brigade-by-Cecil-Woodham-Smith.pdf
    • http://loaminoo.linkpc.net/2097097093091093/Regina-Puckett-s-Short-Tales-of-Horror-by-Regina-Puckett.pdf
    • http://loaminoo.linkpc.net/6093095/The-Midwife-s-Revolt-The-Midwife-Series-1-by-Jodi-Daynard.pdf
    • http://loaminoo.linkpc.net/3092093091098098/The-Midwife-s-Tale-Midwife-Mysteries-1-by-Sam-Thomas.pdf
    • http://loaminoo.linkpc.net/4093091092091090/The-Midwife-and-the-Assassin-Midwife-Mysteries-4-by-Sam-Thomas.pdf
    • http://loaminoo.linkpc.net/8092090091092094/The-7-Principles-of-an-Evangelistic-Life-by-Douglas-M-Cecil.pdf
    • http://loaminoo.linkpc.net/1096095098097097/The-Stricken-Deer-the-Life-of-Cowper-by-David-Cecil.pdf
    • http://loaminoo.linkpc.net/9099092092090096/The-Bridal-Swap-Smoky-Mountain-Matches-2-by-Karen-Kirst.pdf
    • http://loaminoo.linkpc.net/9099092092090093/Reclaiming-His-Past-Smoky-Mountain-Matches-8-by-Karen-Kirst.pdf
    • http://loaminoo.linkpc.net/3097093099098092/Married-by-Christmas-Smoky-Mountain-Matches-5-by-Karen-Kirst.pdf
    • http://loaminoo.linkpc.net/9099092092090095/Married-by-Christmas-Smoky-Mountain-Matches-5-by-Karen-Kirst.pdf
    • http://loaminoo.linkpc.net/9099092092091095/The-Engagement-Charade-Smoky-Mountain-Matches-11-by-Karen-Kirst.pdf
    • http://loaminoo.linkpc.net/2093094099094091/The-Reluctant-Outlaw-Smoky-Mountain-Matches-1-by-Karen-Kirst.pdf
    • http://loaminoo.linkpc.net/4090097094095098/Come-Down-the-Mountain-by-Vian-Smith.pdf
    • http://loaminoo.linkpc.net/2093090098095/A-Midwife-s-Tale-The-Life-of-Martha-Ballard-Based-on-Her-Diary-1785-1812-by-Laurel-Thatcher-Ulrich.pdf
    • http://loaminoo.linkpc.net/109