Malicious PDF — malware analysis report

Static analysis result for SHA-256 efd950a0f950859e…

MALICIOUS

PDF

18.2 KB Created: 2019-05-02 06:16:14 +01:00 Authoring application: mPDF 5.7
MD5: 206f991b83aff4f52e6e98212c0e8baa SHA-1: 796a82173c391b6d34500639ac8ec2fd0717a03c SHA-256: efd950a0f950859e2e8f00a6871ae6409e62d30046dafed04bf9fe358b624350
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, hosted on the loaminoo.linkpc.net domain. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkp
    • http://loaminoo.linkpc.net/8092094097091092/Faith-In-Time-The-Life-Of-Jimmy-Scott-by-David-Ritz.pdf
    • http://loaminoo.linkpc.net/3097090098097099/The-Diamond-as-Big-as-the-Ritz-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/4090091093099096/The-Diamond-as-Big-as-the-Ritz-and-Other-Stories-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/7092099095091093/Un-diamant-gros-comme-le-Ritz-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/9090093097095095/The-First-Time-I-Heard-David-Bowie-by-Scott-Heim.pdf
    • http://loaminoo.linkpc.net/8092094098090090/Tales-of-the-Jazz-Age-The-Curious-Case-of-Benjamin-Button-The-Diamond-As-Big-As-The-Ritz-My-Last-Flappers-amp-more-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/8092094097099097/Ray-Charles-Voice-Of-Soul-by-David-Ritz.pdf
    • http://loaminoo.linkpc.net/8092094097090091/Be-Awesome-How-to-Live-Your-Best-Life-by-Stacey-Ritz.pdf
    • http://loaminoo.linkpc.net/5093091093097098/Fierce-Conversations-Revised-and-Updated-Achieving-Success-at-Work-and-in-Life-One-Conversation-at-a-Time-by-Susan-Scott.pdf
    • http://loaminoo.linkpc.net/1090094094094097095/Everyday-Faith-Practical-Essays-on-Personal-Faith-and-the-Ethical-Choices-We-Face-in-Daily-Life-by-Terry-Pluto.pdf
    • http://loaminoo.linkpc.net/3098090092097090/Target-Tokyo-Jimmy-Doolittle-and-the-Raid-That-Avenged-Pearl-Harbor-by-James-M-Scott.pdf
    • http://loaminoo.linkpc.net/2098095092098099/Jimmy-s-Erotic-Adventure-In-Time-And-Space-Continuum-Episode-1-by-Perie-Wolford.pdf
    • http://loaminoo.linkpc.net/3096098098094092/It-s-a-Wonderful-Life-by-Jimmy-Hawkins.pdf
    • http://loaminoo.linkpc.net/6098098097092098/In-Good-Faith-Joe-Dillard-2-by-Scott-Pratt.pdf
    • http://loaminoo.linkpc.net/4092094096094092/Dizzy-amp-Jimmy-My-Life-with-James-Dean-A-Love-Story-by-Liz-Sheridan.pdf
    • http://loaminoo.linkpc.net/1091094093091090/High-Endeavours-The-Life-and-Legend-of-Robin-Smith-by-Jimmy-Cruickshank.pdf
    • http://loaminoo.linkpc.net/1090093093095096092/Love-s-Orphan-My-Journey-of-Hope-and-Faith-by-Ildiko-Scott.pdf
    • http://loaminoo.linkpc.net/4098096095097098/Faith-and-Courage-in-a-Time-of-Trouble-by-France-J-Pruitt.pdf
    • http://loaminoo.linkpc.net/3092097091097096/The-End-of-Time-Faith-and-the-Fear-in-the-Shadow-of-the-Millennium-by-Damian-Thompson.pdf
    • http://loaminoo.linkpc.net/1099095098092097/Time-Out-1000-Books-to-Change-Your-Life-by-Time-Out-Guides.pdf