Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcd23b8ad4b93961…

MALICIOUS

PDF

17.6 KB Created: 2019-04-30 04:31:29 +01:00 Authoring application: mPDF 5.7
MD5: 0297b20558c171875b77721a37ec16db SHA-1: 043c7141070a72783635ff92d9311f3c10df9790 SHA-256: fcd23b8ad4b93961ebce9d2af70e9325788d6fd8d04f4a95137428c3d8627b8c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The ML classifier strongly indicated maliciousness. The primary heuristic identified a link farm with 23 external links, predominantly using numeric slugs, hosted on the domain loaminoo.linkpc.net. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4096094090091/Born-Confused-Born-Confused-1-by-Tanuja-Desai-Hidier.pdf
    • http://loaminoo.linkpc.net/1091093095093093096/Understanding-What-It-Means-to-Be-Born-Again-And-Things-Pertaining-to-Being-Born-Again-by-Michael-J-Rech.pdf
    • http://loaminoo.linkpc.net/6091093094098/Born-In-Trilogy-Collection-Born-In-1-3-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/4095090097090092/I-ve-Read-My-Bible-And-I-m-Not-Confused-by-Gavin-Cox.pdf
    • http://loaminoo.linkpc.net/4096090091096095/Dared-and-Confused-by-Adara-O-Hare.pdf
    • http://loaminoo.linkpc.net/1096096094092093/Confused-Thoughts-The-Hodgers-Series-1-by-J-G-Cooper.pdf
    • http://loaminoo.linkpc.net/2096097098096093/With-a-Voice-that-is-Often-Still-Confused-But-is-Becoming-Ever-Louder-and-Clearer-by-J-R-Hamantaschen.pdf
    • http://loaminoo.linkpc.net/7091098095099096/Confused-at-the-conference-Chasing-Cameron-1-by-Hanna-Dare.pdf
    • http://loaminoo.linkpc.net/3098099094092093/Bright-Purple-Color-Me-Confused-TrueColors-10-by-Melody-Carlson.pdf
    • http://loaminoo.linkpc.net/1090093094092096/I-Was-Born-There-I-Was-Born-Here-by-Mourid-Barghouti.pdf
    • http://loaminoo.linkpc.net/4095090099090094/Born-Born-1-by-Tara-Brown.pdf
    • http://loaminoo.linkpc.net/4098092091095094/I-Was-Born-There-I-Was-Born-Here-by-Mourid-Barghouti.pdf
    • http://loaminoo.linkpc.net/3096094093095091/Arise-and-Walk-How-does-your-Christian-faith-fit-in-a-confused-world-by-Henry-Bocala.pdf
    • http://loaminoo.linkpc.net/1090097095099094/Soul-Born-Soul-Born-Saga-1-by-Kevin-James-Breaux.pdf
    • http://loaminoo.linkpc.net/1091094099092094099/Magic-Born-The-Elustria-Chronicles-Magic-Born-1-by-Caethes-Faron.pdf
    • http://loaminoo.linkpc.net/8092093099092093/Confessions-of-an-autistic-and-sexually-confused-international-model-The-true-story-of-a-fashion-carreer-by-Agata-Y-M-F-Decroix.pdf
    • http://loaminoo.linkpc.net/1091097090094090090/Shadow-Born-Shadow-Born-Trilogy-1-by-Jamie-Sedgwick.pdf
    • http://loaminoo.linkpc.net/4091097094092098/Shadow-Born-Shadow-Born-Trilogy-1-by-Jamie-Sedgwick.pdf
    • http://loaminoo.linkpc.net/3093096094098091/Born-In-trilogy-collection-Born-In-trilogy-1-3-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/5090095098092/Born-in-Flames-Born-in-Flames-Trilogy-1-by-Candace-Knoebel.pdf