Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9d324f2e3bf1636…

MALICIOUS

PDF

22.1 KB Created: 2019-05-02 17:23:39 +01:00 Authoring application: mPDF 5.7
MD5: b3f12303df3dd180f0db2f7b3fdb9f70 SHA-1: 3777d9f3772b5fbc50d0dc80a2a43c4c7bcd956a SHA-256: d9d324f2e3bf1636b55bea7a44459ea186ea2ec6d54ecd4c4675a34f34ea2140
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The embedded links, such as http://loaminoo.linkpc.net/4093096096098/Teatro-Grottesco-by-Thomas-Ligotti.pdf, are likely intended to direct users to malicious websites or for SEO spam purposes. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4093096096098/Teatro-Grottesco-by-Thomas-Ligotti.pdf
    • http://loaminoo.linkpc.net/9098099095092/Teatro-Grottesco-by-Thomas-Ligotti.pdf
    • http://loaminoo.linkpc.net/3090097097093094/Songs-of-a-Dead-Dreamer-by-Thomas-Ligotti.pdf
    • http://loaminoo.linkpc.net/3093091093099094/Earth-The-Audiobook-A-Visitor-s-Guide-to-the-Human-Race-by-Jon-Stewart.pdf
    • http://loaminoo.linkpc.net/5097094093090/The-Fighting-Chance-The-Human-Race-Book-2-by-Tahnee-Fritz.pdf
    • http://loaminoo.linkpc.net/4091095095099098/A-Troublesome-Inheritance-Genes-Race-and-Human-History-by-Nicholas-J-Wade.pdf
    • http://loaminoo.linkpc.net/8095094092092095/The-Beethoven-Conspiracy-by-Thomas-Hauser.pdf
    • http://loaminoo.linkpc.net/4097094090090094/Beyond-the-Horizon-The-Great-Race-to-Finish-the-First-Human-Powered-Circumnavigation-of-the-Planet-by-Colin-Angus.pdf
    • http://loaminoo.linkpc.net/9091096096096096/Alien-World-Order-The-Reptilian-Plan-to-Divide-and-Conquer-the-Human-Race-by-Len-Kasten.pdf
    • http://loaminoo.linkpc.net/6094098090/A-Conspiracy-in-Belgravia-Lady-Sherlock-2-by-Sherry-Thomas.pdf
    • http://loaminoo.linkpc.net/1094099094093098/The-Whitechapel-Conspiracy-Charlotte-amp-Thomas-Pitt-21-by-Anne-Perry.pdf
    • http://loaminoo.linkpc.net/1090099098098094/The-Origins-of-the-Urban-Crisis-Race-and-Inequality-in-Postwar-Detroit-by-Thomas-J-Sugrue.pdf
    • http://loaminoo.linkpc.net/3092/The-Conspiracy-of-Us-The-Conspiracy-of-Us-1-by-Maggie-Hall.pdf
    • http://loaminoo.linkpc.net/9096099093099091/Formula-5000-in-New-Zealand-amp-Australia-Race-by-Race-by-Wolfgang-Klopfer.pdf
    • http://loaminoo.linkpc.net/7097094094093090/The-Elements-of-Law-Natural-and-Politic-Part-I-Human-Nature-Part-II-de-Corpore-Politico-with-Three-Lives-by-Thomas-Hobbes.pdf
    • http://loaminoo.linkpc.net/5098092097095098/The-betrayal-of-the-white-race-is-real-Has-the-white-race-been-marked-for-genocide-by-Jerry-Henrie.pdf
    • http://loaminoo.linkpc.net/2094097097090098/Forbidden-Gates-How-Genetics-Robotics-Artificial-Intelligence-Synthetic-Biology-Nanotechnology-and-Human-Enhancement-Herald-The-Dawn-Of-TechnoDimensional-Spiritual-Warfare-by-Thomas-Horn.pdf
    • http://loaminoo.linkpc.net/9096099093097098/Formula-A-and-Formula-5000-in-America-Race-by-Race-by-Wolfgang-Klopfer.pdf
    • http://loaminoo.linkpc.net/1091099092093091093/More-Human-Than-Human-Stories-of-Androids-Robots-and-Manufactured-Humanity-by-Neil-Clarke.pdf
    • http://loaminoo.linkpc.net/3098091099097090/The-Geographical-History-of-America-Or-the-Relation-of-Human-Nature-to-the-Human-Mind-by-Gertrude-Stein.pdf
    • http://loaminoo.linkpc.net/6094098090/A-Conspiracy-in-Belgravia-Lady-Sherloc