Malicious PDF — malware analysis report

Static analysis result for SHA-256 f314b2938aae97b5…

MALICIOUS

PDF

21.0 KB Created: 2019-04-30 04:06:58 +01:00 Authoring application: mPDF 5.7
MD5: a47e2e58a6d5414e937b742edc7c5d62 SHA-1: 737d112204a125b4a1487f8946d4f06577e0592c SHA-256: f314b2938aae97b55dc9519a0b35e3dd5b4f651e5588792a767a0bfc8910cf98
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, hosted on the domain loaminoo.linkpc.net. This behavior is indicative of a link farm or a content-spreading operation. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9904

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4094092095095098/Barbarian-Bride-Romancing-the-Romans-2-by-Eva-Scott.pdf
    • http://loaminoo.linkpc.net/2093095093095096/Romancing-the-Wrong-Twin-Romancing-the-1-by-Clare-London.pdf
    • http://loaminoo.linkpc.net/6098095098097095/Romancing-Lady-Cecily-Romancing-0-5-by-Ashley-March.pdf
    • http://loaminoo.linkpc.net/4093098098095090/Brak-the-Barbarian-Versus-the-Sorceress-Brak-the-Barbarian-2-by-John-Jakes.pdf
    • http://loaminoo.linkpc.net/4094098092099090/Invisible-Romans-Prostitutes-outlaws-slaves-gladiators-ordinary-men-and-women-the-Romans-that-history-forgot-by-Robert-Knapp.pdf
    • http://loaminoo.linkpc.net/1090096096091097093/The-Warrior-s-Bride-Lairds-of-the-Loch-3-by-Amanda-Scott.pdf
    • http://loaminoo.linkpc.net/1094099096095097/The-Bride-of-Lammermoor-Tales-of-My-Landlord-3-part-1-by-Walter-Scott.pdf
    • http://loaminoo.linkpc.net/4098099097099/The-Brides-Trilogy-A-3-In-1-Edition-Including-The-Sherbrooke-Bride-The-Hellion-Bride-And-The-Heiress-Bride-by-Catherine-Coulter.pdf
    • http://loaminoo.linkpc.net/6095090097097095/The-Right-Bride-Bride-of-Desire-The-English-Aristocrat-s-Bride-Vacancy-Wife-of-Convenience-by-Sara-Craven.pdf
    • http://loaminoo.linkpc.net/2094099096097093/Romancing-the-Mob-Boss-Romancing-the-Mob-Boss-1-by-Mallory-Monroe.pdf
    • http://loaminoo.linkpc.net/3092093097090094/Romancing-the-Mob-Boss-Romancing-the-Mob-Boss-1-by-Mallory-Monroe.pdf
    • http://loaminoo.linkpc.net/1090091093095096095/Mollie-Bride-of-Georgia-American-Mail-Order-Bride-4-by-Lorrie-Farrelly.pdf
    • http://loaminoo.linkpc.net/4095094094096098/Barbarian-in-the-Garden-by-Zbigniew-Herbert.pdf
    • http://loaminoo.linkpc.net/1093091098093092/The-Barbarian-s-Mistress-by-Nhys-Glover.pdf
    • http://loaminoo.linkpc.net/4091094099092098/Conan-the-Barbarian-by-L-Sprague-de-Camp.pdf
    • http://loaminoo.linkpc.net/3096098096091093/Ronan-The-Barbarian-by-James-Bibby.pdf
    • http://loaminoo.linkpc.net/1091098099099090098/Flappers-and-Philosophers-1920-by-Francis-Scott-Fitzgerald-Francis-Scott-Key-Fitzgerald-September-24-1896---December-21-1940-Known-Professionally-as-F-Scott-Fitzgerald-Was-an-American-Novelist-and-Short-Story-Writer-Whose-Works-Illustrate-by-F-Scott-Fitzgerald.pdf
    • http://loaminoo.linkpc.net/2090090090097095/His-Jilted-Bride-Banks-Brothers-Bride-3-by-Rose-Gordon.pdf
    • http://loaminoo.linkpc.net/1098091095095094/Lauren-s-Barbarian-Icehome-1-by-Ruby-Dixon.pdf
    • http://loaminoo.linkpc.net/7093091090092096/The-Honorable-Barbarian-Novarian-5-by-L-Sprague-de-Camp.pdf
    • http://loaminoo.linkpc.net/1094099096095097/The-Bride-of-Lammermoor-Tales-of-My-Landlord-3-part-1-by-W