Malicious PDF — malware analysis report

Static analysis result for SHA-256 f515e9b690b22a9d…

MALICIOUS

PDF

16.2 KB Created: 2019-05-07 03:38:57 +01:00 Authoring application: mPDF 5.7
MD5: a7f618a8691494e13847e8527f56ddf1 SHA-1: 5cdf221c6ccc3822e48ff82d7f9b7196ee9bdac5 SHA-256: f515e9b690b22a9d7f551a59359028ff31d423375d9fbaed9c16950113aca116
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of external links, forming a link farm, with the primary domain being loaminoo.linkpc.net. The document body was unreadable, but the presence of numerous links suggests a lure to external content, likely malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2098093093098099/The-Stage-Phoenix-Rising-1-by-Shelby-Rebecca.pdf
    • http://loaminoo.linkpc.net/2092099094092092/Taking-Stage-A-Night-with-the-Rock-Star---The-Complete-5-Part-Series-Taking-Stage-1-5-by-Emma-Rose.pdf
    • http://loaminoo.linkpc.net/1091098096092099092/Ryan-s-Dinosaur-and-the-Neon-Fish-Two-Stories-from-Rebecca-s-Collection-by-Rebecca-Lynne-Enden.pdf
    • http://loaminoo.linkpc.net/7090092095095099/Catastrophe-Sekhmet-1-by-Liz-Schulte.pdf
    • http://loaminoo.linkpc.net/6098093093093092/The-Malthusian-Catastrophe-by-Ernesto-Robles.pdf
    • http://loaminoo.linkpc.net/2098094095093095/Catastrophe-1914-Europe-Goes-to-War-by-Max-Hastings.pdf
    • http://loaminoo.linkpc.net/7090092095098097/Nuclear-War-and-Environmental-Catastrophe-by-Noam-Chomsky.pdf
    • http://loaminoo.linkpc.net/3097094093098098/Gum-Girl-1-Catastrophe-Calling-by-Andi-Watson.pdf
    • http://loaminoo.linkpc.net/2094091093092094/Dear-Catastrophe-Waitress-by-Brendan-Halpin.pdf
    • http://loaminoo.linkpc.net/5097093092099093/The-Catastrophe-Aldebaran-1-2-by-Luiz-Eduardo-de-Oliveira-Leo-.pdf
    • http://loaminoo.linkpc.net/7090092094099097/Catastrophe-Body-Swap-1-by-Katrina-Kahler.pdf
    • http://loaminoo.linkpc.net/8098099093092/Still-Life-by-Joe-Donnelly.pdf
    • http://loaminoo.linkpc.net/1090095098098091098/German-Catastrophe-Reflections-amp-Recollections-by-Friedrich-Meinecke.pdf
    • http://loaminoo.linkpc.net/7090092095098095/Lusitania-The-Cultural-History-of-a-Catastrophe-by-Willi-Jasper.pdf
    • http://loaminoo.linkpc.net/7090092095099090/The-Ratastrophe-Catastrophe-The-Illmoor-Chronicles-1-by-David-Lee-Stone.pdf
    • http://loaminoo.linkpc.net/7090092095098094/Sanctioned-Catastrophe-Dark-Titan-1-by-Thomas-A-Watson.pdf
    • http://loaminoo.linkpc.net/3091091097094093/Carla-s-Cloud-Catastrophe-by-Beth-Bence-Reinke.pdf
    • http://loaminoo.linkpc.net/1095093094095095/Levant-Splendour-and-Catastrophe-on-the-Mediterranean-by-Philip-Mansel.pdf
    • http://loaminoo.linkpc.net/4093095099095/Arcade-Catastrophe-The-Candy-Shop-War-2-by-Brandon-Mull.pdf
    • http://loaminoo.linkpc.net/2093092091096092/The-Charge-by-Patrick-Donnelly.pdf