Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc010bf09700b6c3…

MALICIOUS

PDF

16.6 KB Created: 2019-05-01 18:34:03 +01:00 Authoring application: mPDF 5.7
MD5: d8dc298e48c57a2d67a80a7ef896fd91 SHA-1: ca191188ad90bb71f4930721465e72106519fda0 SHA-256: dc010bf09700b6c3913ec07fa54239e8c993ff5176302722b215e1b603e3feaf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO spam or to distribute malicious content. The ML classifier strongly supports a malicious verdict. The primary attack pattern involves directing users to a link farm hosted on loaminoo.linkpc.net.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9913

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098099099092096/Child-of-a-Dead-God-Noble-Dead-Series-1-6-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/2093093093099097/Sister-of-the-Dead-Noble-Dead-Series-1-3-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/2098099099092092/Rebel-Fay-Noble-Dead-Series-1-5-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/2094095098096099/First-and-Last-Sorcerer-Noble-Dead-Saga-Series-3-4-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/1091096090094090/Dhampir-The-Noble-Dead-Saga-Series-1-1-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/3096090097091099/Dead-Days-Season-Six-Dead-Days-Zombie-Apocalypse-Series-Book-6-by-Ryan-Casey.pdf
    • http://loaminoo.linkpc.net/9094095094091091/Dead-Air-The-Dead-Series-1-by-Jon-Schafer.pdf
    • http://loaminoo.linkpc.net/4090097094093093/The-Dead-Detective-Dead-Detective-Series-1-by-J-R-Rain.pdf
    • http://loaminoo.linkpc.net/2093093095096097/Witches-With-the-Enemy-Mist-Torn-Witches-3-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/9092094096093093/Dhampir---Seelendieb-Dhampir-Reihe-2-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/3094096092095090/Witches-in-Red-Mist-Torn-Witches-2-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/2093095094094097/Memories-of-Envy-Vampire-Memories-3-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/4096097098098093/Witches-in-Red-A-Novel-of-the-Mist-Torn-Witches-by-Barb-Hendee.pdf
    • http://loaminoo.linkpc.net/1090095094096095097/Child-of-the-Dead-Spanish-Bit-Saga-23-by-Don-Coldsmith.pdf
    • http://loaminoo.linkpc.net/4094091091097097/Living-with-the-Dead-Twenty-Years-on-the-Bus-with-Garcia-and-the-Grateful-Dead-by-Rock-Scully.pdf
    • http://loaminoo.linkpc.net/2093090096096095/Dead-by-Midnight-Dead-by-Trilogy-1-Griffin-Powell-11-by-Beverly-Barton.pdf
    • http://loaminoo.linkpc.net/2096095097099093/The-First-Inspector-Morse-Omnibus-The-Dead-of-Jericho-Service-of-All-the-Dead-the-Silent-World-of-Nicholas-Quinn-by-Colin-Dexter.pdf
    • http://loaminoo.linkpc.net/4093092095096098/Dead-Even-Dead-3-John-Mancini-5-by-Mariah-Stewart.pdf
    • http://loaminoo.linkpc.net/4093092095096099/Dead-Certain-Dead-2-John-Mancini-4-by-Mariah-Stewart.pdf
    • http://loaminoo.linkpc.net/6094095094098/Dead-Is-a-Killer-Tune-Dead-Is-7-by-Marlene-Perez.pdf
    • http://loaminoo.linkpc.net/3094096092095090/Witches-in-Red-