Malicious PDF — malware analysis report

Static analysis result for SHA-256 f0da169a5def8761…

MALICIOUS

PDF

16.8 KB Created: 2019-05-03 07:38:33 +01:00 Authoring application: mPDF 5.7
MD5: 1e5e88ca0976fcc7dc0b0116e4168f2c SHA-1: 0e34b406bf6a4a1bb0d01ba363ef5f529835df45 SHA-256: f0da169a5def8761a6e02007312f9d2478effd90c54714f0bad7daa8cb4bbdde
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on loaminoo.linkpc.net, suggesting a link farm or content distribution tactic. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/8093098094090092/Mates-for-Monsters-Boxed-Set-by-Tamsin-Ley.pdf
    • http://loaminoo.linkpc.net/5097099097090094/Djinn-s-Desire-Mates-for-Monsters-3-by-Tamsin-Ley.pdf
    • http://loaminoo.linkpc.net/4094098096095096/Spirit-Wolves-Volume-1-A-Mate-Beyond-Their-Reach-Mates-in-Life-and-Death-Two-Mates-for-a-Magistrate-by-Scarlet-Hyacinth.pdf
    • http://loaminoo.linkpc.net/6090099098098099/Gila-Monsters-Learn-About-Gila-Monsters-and-Enjoy-Colorful-Pictures---Look-and-Learn-50-Photos-of-Gila-Monsters-by-Becky-Wolff.pdf
    • http://loaminoo.linkpc.net/9092091094091/Pacific-Monsters-Fox-Spirit-Books-of-Monsters-4-by-Margr-t-Helgad-ttir.pdf
    • http://loaminoo.linkpc.net/3098098091097092/Lights-Camera-Monsters-Monsters-in-Hollywood-1-by-Lila-Dubois.pdf
    • http://loaminoo.linkpc.net/9095097097095/African-Monsters-Fox-Spirit-Books-of-Monsters-2-by-Margr-t-Helgad-ttir.pdf
    • http://loaminoo.linkpc.net/1098091090095093/Mates-Dates-and-Sizzling-Summers-Mates-Dates-12-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/2098090094099096/Mates-Dates-and-Chocolate-Cheats-Mates-Dates-10-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/5090091091094093/Mates-Dates-and-Diamond-Destiny-Mates-Dates-11-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/1098091090099096/Mates-Dates-and-Inflatable-Bras-Mates-Dates-1-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/1098091092096091/Mates-Dates-and-Tempting-Trouble-Mates-Dates-8-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/1098091092098090/Mates-Dates-and-Sequin-Smiles-Mates-Dates-7-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/5090090090096095/Mates-Dates-and-Sleepover-Secrets-Mates-Dates-4-by-Cathy-Hopkins.pdf
    • http://loaminoo.linkpc.net/2098093090099090/Love-in-a-Time-of-Monsters-Golden-Age-of-Monsters-1-by-Teresa-Yea.pdf
    • http://loaminoo.linkpc.net/2096095098091092/Sleeping-with-Monsters-Playing-With-Monsters-2-by-Amelia-Hutchins.pdf
    • http://loaminoo.linkpc.net/3095094095098091/Sleeping-with-Monsters-Playing-with-Monsters-2-by-Amelia-Hutchins.pdf
    • http://loaminoo.linkpc.net/3093097096094099/Tamsin-by-Peter-S-Beagle.pdf
    • http://loaminoo.linkpc.net/4092097096090099/The-Last-of-the-Monsters-Monsters-in-Hollywood-6-by-Lila-Dubois.pdf
    • http://loaminoo.linkpc.net/1090090094095094096/Tamsin-Harte-by-Malcolm-MacDonald.pdf