Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe264c209084ef3e…

MALICIOUS

PDF

16.8 KB Created: 2019-04-30 18:38:54 +01:00 Authoring application: mPDF 5.7
MD5: d50e6d293fe28174c1306fc207ac674b SHA-1: 49ab61aa2532634bc6d033e1b32571e1e1e69aef SHA-256: fe264c209084ef3ec132bbfc271d4948d05f6586248aa3ce663a1dfd1c634d2e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by an ML classifier and contains a large number of embedded links, identified as a PDF SEO link farm. These links point to various PDF files hosted on 'loaminoo.linkpc.net', suggesting a tactic to manipulate search engine results or distribute unwanted content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9095099095091/Best-New-Horror-21-The-Mammoth-Book-of-Best-New-Horror-21-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/3096097097097092/Best-New-Horror-16-The-Mammoth-Book-of-Best-New-Horror-16-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/2096091096097/Best-New-Horror-12-The-Mammoth-Book-of-Best-New-Horror-12-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/4090098094090090/Best-New-Horror-22-The-Mammoth-Book-of-Best-New-Horror-22-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/9095097092091/Best-New-Horror-20-The-Mammoth-Book-of-Best-New-Horror-20-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/9095097094090/Best-New-Horror-14-The-Mammoth-Book-of-Best-New-Horror-14-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/4090098094092096/The-Mammoth-Book-of-Body-Horror-by-Paul-Kane.pdf
    • http://loaminoo.linkpc.net/4090096091097098/The-Mammoth-Book-of-Zombies-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/3096090091097092/The-Mammoth-Book-of-Zombie-Apocalypse-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/6099098094093098/Blood-Lite-An-Anthology-of-Humorous-Horror-Stories-Presented-by-the-Horror-Writers-Association-by-Kevin-J-Anderson.pdf
    • http://loaminoo.linkpc.net/1091091093098090/Thirteen-Tales-of-Horror-Point-Horror-13-s-by-T-Pines.pdf
    • http://loaminoo.linkpc.net/2094090098097094/The-Amityville-Horror-II-by-John-G-Jones.pdf
    • http://loaminoo.linkpc.net/9096091094091/The-First-Humdrumming-Book-of-Horror-Stories-by-Ian-Alexander-Martin.pdf
    • http://loaminoo.linkpc.net/5090093092097093/The-Book-Splash-Horror-Story-by-Cassia-Brightmore.pdf
    • http://loaminoo.linkpc.net/9095099098091/The-Second-Humdrumming-Book-of-Horror-Stories-by-Ian-Alexander-Martin.pdf
    • http://loaminoo.linkpc.net/2095091092093092/Demonic-Visions-50-Horror-Tales-4-Demonic-Visions-50-Horror-Tales-4-by-Chris-Robertson.pdf
    • http://loaminoo.linkpc.net/1090095096098098093/Weiser-Book-of-Horror-and-the-Occult-Hidden-Magic-Occult-Truths-and-the-Stories-That-Started-It-All-by-Lon-Milo-DuQuette.pdf
    • http://loaminoo.linkpc.net/9096091094092/The-Black-Book-of-Horror-by-Charles-Black.pdf
    • http://loaminoo.linkpc.net/2096090095095/A-Book-of-Horrors-by-Stephen-Jones.pdf
    • http://loaminoo.linkpc.net/3099095099099094/Oh-The-Horror-by-Jaime-Johnesee.pdf
    • http://loaminoo.linkpc.net