Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa706a18313a4300…

MALICIOUS

PDF

21.2 KB Created: 2019-05-01 06:09:38 +01:00 Authoring application: mPDF 5.7
MD5: 313f9ede9e43d5afd6b8e39f3699bf75 SHA-1: da179fa61bf525b605c8879253aaebd486e16242 SHA-256: fa706a18313a430014ae931fccbe41cf1ef2648bf467f2a0a73e0addd7f120e3
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a critical heuristic for containing a mass external link farm, with 25 numeric-slug links pointing to external PDFs. The ML classifier also strongly indicated maliciousness. While no scripts were extracted, the structure and the presence of numerous links suggest a distribution or SEO manipulation tactic. The primary IOCs are the external URLs embedded within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091094092093095092/Mother-s-Love-Inspiring-True-Stories-from-the-Animal-Kingdom-by-Melina-Gerosa-Bellows.pdf
    • http://loaminoo.linkpc.net/2093097098090093/Alien-Hand-Syndrome-and-Other-Too-Weird-Not-To-Be-True-Stories-by-Alan-Bellows.pdf
    • http://loaminoo.linkpc.net/4099095093091096/Inspiring-Animal-Tales-Heartwarming-Stories-of-Courage-and-Devotion-by-Roxanne-Willems-Snopek.pdf
    • http://loaminoo.linkpc.net/1090094092092096/Unlikely-Friendships-47-Remarkable-Stories-from-the-Animal-Kingdom-by-Jennifer-S-Holland.pdf
    • http://loaminoo.linkpc.net/1091095090098098093/What-Animals-Tell-Me-True-Stories-of-an-Animal-Communicator-by-Monica-Diedrich.pdf
    • http://loaminoo.linkpc.net/3096097093093095/Animal-Miracles-Inspirational-and-Heroic-True-Stories-by-Brad-Steiger.pdf
    • http://loaminoo.linkpc.net/1090092090097092/Love-Has-a-Price-Tag-Inspiring-Stories-That-Will-Open-Your-Heart-to-Life-s-Little-Miracles-by-Elisabeth-Elliot.pdf
    • http://loaminoo.linkpc.net/4099099092097097/So-True-a-Love-Daughters-of-His-Kingdom-2-by-Amber-Lynn-Perry.pdf
    • http://loaminoo.linkpc.net/2095095090093092/To-My-Best-Girl-Courage-Honor-and-Love-in-the-Civil-War-The-Inspiring-Life-Stories-of-Rufus-Dawes-and-Mary-Gates-by-Steve-Magnusen.pdf
    • http://loaminoo.linkpc.net/6092093098093092/Kona-Animal-Stories-of-Love-by-Fatou-N-39-Diaye.pdf
    • http://loaminoo.linkpc.net/7097094091091/Message-from-an-Unknown-Chinese-Mother-Stories-of-Loss-and-Love-by-Xinran.pdf
    • http://loaminoo.linkpc.net/1090097099093095098/Josie-s-Story-A-Mother-s-Inspiring-Crusade-to-Make-Medical-Care-Safe-by-Sorrel-King.pdf
    • http://loaminoo.linkpc.net/6098091098093093/True-Irish-Ghost-Stories-True-Hauntings-Paranormal-Investigator-Supernatural-Phenomena-from-the-real-stories---Annotated-Who-are-Celts-People-by-St-John-D-Seymour.pdf
    • http://loaminoo.linkpc.net/4096098099096091/Haatchi-amp-Little-B-The-Inspiring-True-Story-of-One-Boy-and-His-Dog-by-Wendy-Holden.pdf
    • http://loaminoo.linkpc.net/5099096095096/Just-a-Boy-An-Inspiring-and-Heartwarming-True-Story-by-Casey-Watson.pdf
    • http://loaminoo.linkpc.net/4092099098095090/What-Your-Mama-Never-Told-You-True-Stories-About-Sex-and-Love-by-Tara-Roberts.pdf
    • http://loaminoo.linkpc.net/1091098098097090091/Beautiful-on-the-Mountain-An-Inspiring-True-Story-by-Jeannie-Light.pdf
    • http://loaminoo.linkpc.net/4095098093094/My-True-Love-Gave-to-Me-Twelve-Holiday-Stories-by-Stephanie-Perkins.pdf
    • http://loaminoo.linkpc.net/1090091096097098/Quest-for-Love-True-Stories-of-Passion-and-Purity-by-Elisabeth-Elliot.pdf
    • http://loaminoo.linkpc.net/7095095090096/True-Crime-Stories-10-Heinous-True-Crime-Stories-Of-Sickly-Serial-Killers-Murderers-And-Sociopaths-by-Travis-S-Kennedy.pdf
    • http://loaminoo.linkpc.net/1090092090097092/Love-Has-a-Pri