Malicious PDF — malware analysis report

Static analysis result for SHA-256 19ab937675435895…

MALICIOUS

PDF

13.6 KB Created: 2019-05-01 19:30:09 +01:00 Authoring application: mPDF 5.7
MD5: c59f3224d10fa4c3e6452e025e6a87cd SHA-1: ab41bf2f4771f68252da3d6a9c5c7e2aad2957b0 SHA-256: 19ab9376754358957d13fa4c7dc87991cc8633650d30cd7fd04147221d51f67d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links pointing to external PDF files hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a phishing lure designed to redirect users to potentially malicious content. The ML classifier also flagged this PDF as malicious, supporting the suspicious nature of the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092093091095094/Bikini-Planet-by-David-S-Garnett.pdf
    • http://loaminoo.linkpc.net/8098091090095/Lady-into-Fox-by-David-Garnett.pdf
    • http://loaminoo.linkpc.net/9094094097096090/Shadowbreed-Konrad-2-by-David-S-Garnett.pdf
    • http://loaminoo.linkpc.net/9094094097090096/The-Konrad-Saga-Konrad-1-3-by-David-S-Garnett.pdf
    • http://loaminoo.linkpc.net/1091096098093096/Jumping-Off-the-Planet-Dingilliad-1-by-David-Gerrold.pdf
    • http://loaminoo.linkpc.net/4094097098093092/Mars-Our-Future-on-the-Red-Planet-by-Leonard-David.pdf
    • http://loaminoo.linkpc.net/4099098094093098/Battle-for-the-Planet-of-the-Apes-by-David-Gerrold.pdf
    • http://loaminoo.linkpc.net/9090095092092/The-Only-Living-Boy-1-Prisoner-of-the-Patchwork-Planet-by-David-Gallaher.pdf
    • http://loaminoo.linkpc.net/5092097097095093/Endangered-Planet-Kingfisher-Knowledge-by-David-Burnie.pdf
    • http://loaminoo.linkpc.net/2095098096093092/The-Living-Planet-A-Portrait-of-the-Earth-by-David-Attenborough.pdf
    • http://loaminoo.linkpc.net/2091097090094/Black-Planet-Facing-Race-During-an-NBA-Season-by-David-Shields.pdf
    • http://loaminoo.linkpc.net/4099095092097092/Planet-Hong-Kong-Popular-Cinema-and-the-Art-of-Entertainment-by-David-Bordwell.pdf
    • http://loaminoo.linkpc.net/7098097097090099/The-Dawn-of-the-Color-Photograph-Albert-Kahn-s-Archives-of-the-Planet-by-David-Okuefuna.pdf
    • http://loaminoo.linkpc.net/3091091096092095/The-Family-From-One-End-Street-by-Eve-Garnett.pdf
    • http://loaminoo.linkpc.net/3090098094093095/The-Scotsman-by-Juliana-Garnett.pdf
    • http://loaminoo.linkpc.net/2099096090092/The-Last-Days-of-Wolf-Garnett-by-Clifton-Adams.pdf
    • http://loaminoo.linkpc.net/1090094094093090099/When-Is-a-Planet-Not-a-Planet-The-Story-of-Pluto-by-Elaine-Scott.pdf
    • http://loaminoo.linkpc.net/3090092093093093/Ice-Planet-Holiday-Ice-Planet-Barbarians-4-5-by-Ruby-Dixon.pdf
    • http://loaminoo.linkpc.net/2098090099095099/Low-Tide-Bikini-by-Lyla-Dune.pdf
    • http://loaminoo.linkpc.net/1099099096095095/White-Bikini-Panties-by-Kelly-James-Enger.pdf