Malicious PDF — malware analysis report

Static analysis result for SHA-256 dd207fa21adeaa97…

MALICIOUS

PDF

19.9 KB Created: 2019-04-30 04:04:47 +01:00 Authoring application: mPDF 5.7
MD5: 33c28efc8147124824b2e520b604ba7a SHA-1: 3244039ad66b50186a626c612e1ebd0791840e82 SHA-256: dd207fa21adeaa9789dcbe1c74b1f62f08f317ac9ae93a5b04b96fc0ce151365
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a lure to download further content. The ML classifier strongly flagged this PDF as malicious, and the heuristic 'PDF_SEO_LINK_FARM' confirms the presence of numerous external links, suggesting a malicious intent to redirect users. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6091094095094/Bright-Days-Dark-Nights-With-Charles-Spurgeon-in-Triumph-Over-Emotional-Pain-by-Elizabeth-R-Skoglund.pdf
    • http://loaminoo.linkpc.net/9097092090098/All-of-Grace-by-Charles-Haddon-Spurgeon.pdf
    • http://loaminoo.linkpc.net/5095097096092098/All-of-Grace-by-Charles-Haddon-Spurgeon.pdf
    • http://loaminoo.linkpc.net/9094097098093096/A-Serious-Charge-against-Unbelievers-by-Charles-Haddon-Spurgeon.pdf
    • http://loaminoo.linkpc.net/6094090096093097/Sermons-on-Proverbs-by-Charles-Haddon-Spurgeon.pdf
    • http://loaminoo.linkpc.net/5097097099098091/Commenting-and-Commentaries-by-Charles-Haddon-Spurgeon.pdf
    • http://loaminoo.linkpc.net/6094090097093090/Farm-Sermons-by-Charles-Haddon-Spurgeon.pdf
    • http://loaminoo.linkpc.net/3098097094092/Morning-and-Evening-Based-on-the-English-Standard-Version-by-Charles-Haddon-Spurgeon.pdf
    • http://loaminoo.linkpc.net/1092092094094/Lakota-Legacy-Wolf-Dreamer-Cowboy-Days-And-Indian-Nights-Seven-Days-by-Madeline-Baker.pdf
    • http://loaminoo.linkpc.net/1092090090098094/Bright-Lights-and-White-Nights-by-Andrew-Carter.pdf
    • http://loaminoo.linkpc.net/3098092097099097/Caress-of-Pleasure-A-Dark-Pleasures-Novella-Dark-Pleasures-3-5-1001-Dark-Nights-17-by-Julie-Kenner.pdf
    • http://loaminoo.linkpc.net/4098097094096099/Tangled-Dark-Protectors-7-8-1001-Dark-Nights-58-by-Rebecca-Zanetti.pdf
    • http://loaminoo.linkpc.net/6091095091094095/Before-You-Judge-Me-The-Triumph-and-Tragedy-of-Michael-Jackson-s-Last-Days-by-Tavis-Smiley.pdf
    • http://loaminoo.linkpc.net/3094099090090093/30-Days-of-Night-Vol-2-Dark-Days-by-Steve-Niles.pdf
    • http://loaminoo.linkpc.net/8092093095094/Beautiful-Days-Bright-Young-Things-2-by-Anna-Godbersen.pdf
    • http://loaminoo.linkpc.net/2099093098098090/Beautiful-Days-Bright-Young-Things-2-by-Anna-Godbersen.pdf
    • http://loaminoo.linkpc.net/2092095092092090/All-the-Days-and-Nights-by-Niven-Govinden.pdf
    • http://loaminoo.linkpc.net/6094095096095098/Days-and-Nights-by-Alfred-Jarry.pdf
    • http://loaminoo.linkpc.net/1094094096095093/Moonlit-Days-and-Nights-by-D-H-Toole.pdf
    • http://loaminoo.linkpc.net/9096094090095093/Back-Pain-Get-Your-Back-BACK---Your-Self-Help-Guide-on-How-to-Treat-Back-Pain-Naturally-and-Without-Drugs-Understanding-the-Anatomy-of-the-Back-Holistic-Pain-Holistic-Healing-Back-Pain-Book-1-by-Joschi-Schwarz.pdf
    • http://loaminoo.linkpc.net/3098092097099097/Caress-of-Pleasure-A-Dark-Pleasures-No