Malicious PDF — malware analysis report

Static analysis result for SHA-256 dfc88a4ac3d884e8…

MALICIOUS

PDF

17.0 KB Created: 2019-05-02 01:20:48 +01:00 Authoring application: mPDF 5.7
MD5: a1ffe3e69d2ed0111c60d3f99d26d638 SHA-1: e32365261ab14f1b180aa2d8af9f90d66ce26538 SHA-256: dfc88a4ac3d884e8b8f363d8fff7b1e0d63ae308d3d6ac73a9e4dce29ef89d66
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of links to external PDF files, hosted on the suspicious domain loaminoo.linkpc.net. This heuristic firing suggests a link farm or a method to distribute further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the immediate user-facing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1094097092091094/Invisible-Love-Letter-Love-Letter-1-by-Callie-Anderson.pdf
    • http://loaminoo.linkpc.net/1090099098092098097/Invisible-Love-Letter-Love-Letter-1-by-Callie-Anderson.pdf
    • http://loaminoo.linkpc.net/1090099098093091092/Endless-Love-Letter-Love-Letter-2-by-Callie-Anderson.pdf
    • http://loaminoo.linkpc.net/4095092096096097/Love-Letter-Duet-The-Encore-Edition-by-Callie-Anderson.pdf
    • http://loaminoo.linkpc.net/2094093093090097/The-Love-Letter-by-Rachel-Hauck.pdf
    • http://loaminoo.linkpc.net/1097093093099097/I-Sent-a-Letter-to-My-Love-by-Bernice-Rubens.pdf
    • http://loaminoo.linkpc.net/2092091099095099/Love-is-a-Four-Letter-Word-by-Claire-Calman.pdf
    • http://loaminoo.linkpc.net/1094097092092096/A-Love-Letter-to-Whiskey-by-Kandi-Steiner.pdf
    • http://loaminoo.linkpc.net/4091098091092099/A-Love-Letter-from-the-Girls-Who-Feel-Everything-by-Brittainy-C-Cherry.pdf
    • http://loaminoo.linkpc.net/1097097091097095/Secret-Love-Letter-The-Jealousy-Garden-1-by-Tina-M-Randolph.pdf
    • http://loaminoo.linkpc.net/1090093091092090097/Divergent-Parody-2-To-Four-With-Love-a-Letter-From-Tris-by-Stir-Ling.pdf
    • http://loaminoo.linkpc.net/9099091098094091/Letter-Art-2-Cool-amp-Colorful-Letter-Designs-to-Draw-by-Lauren-Scheuer.pdf
    • http://loaminoo.linkpc.net/4090090097095092/Tegami-Bachi-Vol-2-Letter-Bee-The-Letter-to-Jiggy-Pepper-by-Hiroyuki-Asada.pdf
    • http://loaminoo.linkpc.net/4097096092093091/Bread-and-Wine-A-Love-Letter-to-Life-Around-the-Table-with-Recipes-by-Shauna-Niequist.pdf
    • http://loaminoo.linkpc.net/6092090090095097/A-Letter-to-the-Reverend-Mr-Thomas-Carte-Author-of-the-Full-Answer-to-the-Letter-from-a-Bystander-by-a-Gentleman-of-Cambridge-by-Corbyn-Morris.pdf
    • http://loaminoo.linkpc.net/6091092090090091/Letter-By-Letter-by-Louise-Maheux-Forcier.pdf
    • http://loaminoo.linkpc.net/3095090098098097/My-First-Love-Love-Stories-For-Young-Adults-1-by-Callie-West.pdf
    • http://loaminoo.linkpc.net/4094098090097096/Letter-from-a-Christian-Citizen-A-Response-to-quot-Letter-to-a-Christian-Nation-quot-by-Sam-Harris-by-Douglas-Wilson.pdf
    • http://loaminoo.linkpc.net/2094099092091098/Crooked-Letter-Crooked-Letter-by-Tom-Franklin.pdf
    • http://loaminoo.linkpc.net/1097092094090092/A-Chance-to-Love-Again-Oklahoma-Lovers-3-by-Callie-Hutton.pdf
    • http://loaminoo.linkpc.net/1090093091092090097/Divergent-Parody-2-To-Four-With-Love-a-