Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7a12eb93e859bdd…

MALICIOUS

PDF

21.6 KB Created: 2019-05-02 01:07:17 +01:00 Authoring application: mPDF 5.7
MD5: 167c9920e061f27e995b2943d9d561c4 SHA-1: f99a3fac2361ea8d543840f1513dd6e705945edf SHA-256: e7a12eb93e859bdde6aaaf3a31bcf2c9f25dbb0cdb6c82cf7b5941b5b1acfb3c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to a single domain. The ML classifier also strongly indicated maliciousness. The primary attack pattern appears to be SEO manipulation or a link farm designed to redirect users to potentially malicious content hosted on loaminoo.linkpc.net.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6090095090096093/Too-Late-to-Run-Mara-Cunningham-Series-3-by-John-Perich.pdf
    • http://loaminoo.linkpc.net/6092090095094/John-Patrick-Norman-McHennessy-The-Boy-Who-Was-Always-Late-by-John-Burningham.pdf
    • http://loaminoo.linkpc.net/4096098098098096/Beautiful-Trash-Scarlet-Briar-Series-1-by-Mara-Ryder.pdf
    • http://loaminoo.linkpc.net/1098090098097094/The-Big-Switch-It-s-never-too-late-by-John-Thomas.pdf
    • http://loaminoo.linkpc.net/1090091097090096099/Red-Right-Return-Buck-Reilly-Adventure-1-by-John-H-Cunningham.pdf
    • http://loaminoo.linkpc.net/1090091097090098094/Green-To-Go-Buck-Reilly-Adventure-2-by-John-H-Cunningham.pdf
    • http://loaminoo.linkpc.net/6090094098097092/Cunningham-s-Encyclopedia-of-Crystal-Gem-amp-Metal-Magic-by-Scott-Cunningham.pdf
    • http://loaminoo.linkpc.net/1090091097091095096/Crystal-Blue-Buck-Reilly-Adventure-3-by-John-H-Cunningham.pdf
    • http://loaminoo.linkpc.net/6090094098096098/Cunningham-s-Encyclopedia-of-Wicca-in-the-Kitchen-by-Scott-Cunningham.pdf
    • http://loaminoo.linkpc.net/6097098091098/The-Evolution-of-Mara-Dyer-Mara-Dyer-2-by-Michelle-Hodkin.pdf
    • http://loaminoo.linkpc.net/3096093095091091/The-Unbecoming-of-Mara-Dyer-Mara-Dyer-1-by-Michelle-Hodkin.pdf
    • http://loaminoo.linkpc.net/5097097093098/The-Evolution-of-Mara-Dyer-Mara-Dyer-2-by-Michelle-Hodkin.pdf
    • http://loaminoo.linkpc.net/3095097098099094/The-Unbecoming-of-Mara-Dyer-Mara-Dyer-1-by-Michelle-Hodkin.pdf
    • http://loaminoo.linkpc.net/3092095092094/The-Unbecoming-of-Mara-Dyer-Mara-Dyer-1-by-Michelle-Hodkin.pdf
    • http://loaminoo.linkpc.net/7092096097091/The-Unbecoming-of-Mara-Dyer-Mara-Dyer-1-by-Michelle-Hodkin.pdf
    • http://loaminoo.linkpc.net/8096097093096090/The-Memoirs-of-Baron-de-Marbot-Late-Lieutenant---General-in-the-French-Army-by-Arthur-John-Butler.pdf
    • http://loaminoo.linkpc.net/8096097095092094/The-Memoirs-of-Baron-de-Marbot-Late-Lieutenant-General-in-the-French-Army-Volume-1-by-Arthur-John-Butler.pdf
    • http://loaminoo.linkpc.net/1093098097097093/How-Late-it-Was-How-Late-by-James-Kelman.pdf
    • http://loaminoo.linkpc.net/1093093095097094/Orson-Scott-Card-Series-Reading-Order-amp-Checklist-Series-List-in-Order---Ender-Series-Formic-War-Series-Shadow-Series-Ender-Series-amp-Tales-of-Alvin-Maker-Series-Listabook-Series-Order-Book-15-by-Listabook.pdf
    • http://loaminoo.linkpc.net/5094094098094097/Brandon-Mull-Books-Checklist-and-Series-in-Order-2017-Beyonders-Series-in-Order-Candy-Shop-War-Series-in-Order-Dragonwatch-Series-in-Order-Fablehaven-Series-Five-Kingdoms-Series-and-More-by-List-To-Read.pdf
    • http://loaminoo.linkpc.net/3096093095091091/The-Unbecoming-of-Mara-Dyer-Mara-Dyer-1-by-Michelle-H