Malicious PDF — malware analysis report

Static analysis result for SHA-256 19d4238cf6f5d118…

MALICIOUS

PDF

17.6 KB Created: 2019-04-30 01:57:24 +01:00 Authoring application: mPDF 5.7
MD5: f20950fc6803fa9bbb0c12866617e786 SHA-1: 75b23c63c4309c25f2657841ca7fb546eca35986 SHA-256: 19d4238cf6f5d1188e2cbfcc4cfde2b972bed0e4b74de5784e9a114407c76e3e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, hosted on the domain loaminoo.linkpc.net. This heuristic firing, combined with the ML classifier's high confidence, suggests a link-farming or redirection tactic. No scripts were extracted, and the document body was heavily corrupted, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8090093090096091/You-Are-Not-My-Son-Fairmont-Boys-3-by-Jay-Argent.pdf
    • http://loaminoo.linkpc.net/8090093090096092/Swimmer-Boy-Fairmont-Boys-1-by-Jay-Argent.pdf
    • http://loaminoo.linkpc.net/5099093091093093/10-Top-Tips-on-Supporting-Kinship-Placements-Hedi-Argent-by-Hedi-Argent.pdf
    • http://loaminoo.linkpc.net/1091099091098098096/Real-Boys-Boys-Will-Do-Boys-6-by-Nica-Berry.pdf
    • http://loaminoo.linkpc.net/7096097099097/Jim-Averbeck-Presents-a-Hitch-at-the-Fairmont-by-Jim-Averbeck.pdf
    • http://loaminoo.linkpc.net/1099092091097096/The-Way-of-Boys-Raising-Healthy-Boys-in-a-Challenging-and-Complex-World-by-Anthony-Rao.pdf
    • http://loaminoo.linkpc.net/6099093090099098/Boys-Will-Be-Boys-Breaking-the-Link-Between-Masculinity-and-Violence-by-Myriam-Miedzian.pdf
    • http://loaminoo.linkpc.net/2096097099091090/Boys-Adrift-The-Five-Factors-Driving-the-Growing-Epidemic-of-Unmotivated-Boys-and-Underachieving-Young-Men-by-Leonard-Sax.pdf
    • http://loaminoo.linkpc.net/1094090097097091/Boys-Will-Be-Boys-The-Glory-Days-and-Party-Nights-of-the-Dallas-Cowboys-Dynasty-by-Jeff-Pearlman.pdf
    • http://loaminoo.linkpc.net/6097096098091095/The-Boys-Tomo-1-El-nombre-del-juego-The-Boys-1-by-Garth-Ennis.pdf
    • http://loaminoo.linkpc.net/3099099096091091/Raising-Boys-Why-Boys-Are-Different-and-How-to-Help-Them-Become-Happy-and-Well-Balanced-Men-by-Steve-Biddulph.pdf
    • http://loaminoo.linkpc.net/5099093091090093/Whatever-Happened-to-Adam-by-Hedi-Argent.pdf
    • http://loaminoo.linkpc.net/6096097099094/Sebastian-Family-of-Lies-1-by-Sam-Argent.pdf
    • http://loaminoo.linkpc.net/5095091099090094/Josh-And-Jaz-Have-Three-Mums-by-Hedi-Argent.pdf
    • http://loaminoo.linkpc.net/8090093090095096/King-of-Argent-by-John-T-Phillifent.pdf
    • http://loaminoo.linkpc.net/1099092098090090/Game-Boys-Boys-in-Love-1-by-Rochelle-H-Ragnarok.pdf
    • http://loaminoo.linkpc.net/1092090097092/Who-Needs-Boys-The-Girlfriend-s-Guide-to-Boys-3-by-Stephie-Davis.pdf
    • http://loaminoo.linkpc.net/2090096091098092/The-Bad-Boys-Reluctant-Woman-The-Law-Castle-Bad-Boys-2-by-Sam-Crescent.pdf
    • http://loaminoo.linkpc.net/7096094092099093/Chevaliers-Noirs-Vif-Argent-by-Hugues-Delalande.pdf
    • http://loaminoo.linkpc.net/2096096094094092/Witches-for-Hire-Odd-Jobs-Book-1-by-Sam-Argent.pdf
    • http://loaminoo.linkpc.net/1094090097097091/Boys-Will-Be-Boys-The-Glory-Days-and-Party-Nig