Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9af5595eee69cb8…

MALICIOUS

PDF

15.8 KB Created: 2019-04-30 04:11:05 +01:00 Authoring application: mPDF 5.7
MD5: 9eedc2dfe960a67590e0efcc6ca47153 SHA-1: c739898b668a6d12e4b60c32a95af7bdc6301e6f SHA-256: d9af5595eee69cb8d88c8fbd46b1735924f33ec9a2c4771f365b615237793a6f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to other PDF files, forming a link farm. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a link farm. The document body, though obfuscated, contains numerous URLs pointing to what appear to be book titles, suggesting a lure to download further content. The primary attack pattern involves directing users to a malicious domain hosting a large number of potentially harmful files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9892

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/1094096091099097/The-Pirate-s-Stowaway-Bride-by-Anne-Stryker.pdf
    • http://loaminoo.linkpc.net/1099098099098097/Hovering-Above-Chaos-by-Anne-Stryker.pdf
    • http://loaminoo.linkpc.net/1092099099092093/The-Pirate-Bride-by-Shannon-Drake.pdf
    • http://loaminoo.linkpc.net/4099093097097095/Pirate-Spirit-The-Adventures-of-Anne-Bonney-by-Jeffery-S-Williams.pdf
    • http://loaminoo.linkpc.net/4099094094092094/The-Pirate-Trial-of-Anne-Bonny-and-Mary-Read-by-Tamara-J-Eastman.pdf
    • http://loaminoo.linkpc.net/3094093090092095/The-Best-Man-s-Bride-by-Anne-McAllister.pdf
    • http://loaminoo.linkpc.net/2090093093092090/Unwanted-Bride-by-Anne-Hampson.pdf
    • http://loaminoo.linkpc.net/1091096090096096098/The-Edinburgh-Bride-by-Anne-Douglas.pdf
    • http://loaminoo.linkpc.net/6093099096092090/The-Alexakis-Bride-by-Anne-McAllister.pdf
    • http://loaminoo.linkpc.net/7091092099098096/Castillo-s-Bride-by-Anne-Marie-Duquette.pdf
    • http://loaminoo.linkpc.net/2093091094096095/The-Summer-Bride-Chance-Sisters-4-by-Anne-Gracie.pdf
    • http://loaminoo.linkpc.net/1091095099092/Bride-by-Mistake-Devil-Riders-5-by-Anne-Gracie.pdf
    • http://loaminoo.linkpc.net/4090090092099094/The-Winter-Bride-Chance-Sisters-2-by-Anne-Gracie.pdf
    • http://loaminoo.linkpc.net/7090099099/The-MacKinnon-s-Bride-The-Highland-Brides-1-by-Tanya-Anne-Crosby.pdf
    • http://loaminoo.linkpc.net/2097099095098095/The-MacKinnon-s-Bride-The-Highland-Brides-1-by-Tanya-Anne-Crosby.pdf
    • http://loaminoo.linkpc.net/4096092093091095/The-MacKinnon-s-Bride-The-Highland-Brides-1-by-Tanya-Anne-Crosby.pdf
    • http://loaminoo.linkpc.net/4092097099095097/Stowaway-Travelers-2-by-Becky-Black.pdf
    • http://loaminoo.linkpc.net/2098097098098096/Stowaway-Travelers-2-by-Becky-Black.pdf
    • http://loaminoo.linkpc.net/4098099097099/The-Brides-Trilogy-A-3-In-1-Edition-Including-The-Sherbrooke-Bride-The-Hellion-Bride-And-The-Heiress-Bride-by-Catherine-Coulter.pdf
    • http://loaminoo.linkpc.net/6095090097097095/The-Right-Bride-Bride-of-Desire-The-English-Aristocrat-s-Bride-Vacancy-Wife-of-Convenience-by-Sara-Craven.pdf