Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e7bdbd7d5fdea45…

MALICIOUS

PDF

18.0 KB Created: 2019-05-04 16:11:06 +01:00 Authoring application: mPDF 5.7
MD5: ab50cec35ea9ed7b9dc126d41950a2bc SHA-1: 09c905fcf39aed95186b69fc4a994d8f2128cadf SHA-256: 1e7bdbd7d5fdea450842f0d02ea7460b0eddfe932d76560324aded588ab0f22a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDFs hosted on the domain 'loaminoo.linkpc.net'. This heuristic firing, combined with the ML classifier's high confidence, suggests a link-farming or redirection tactic. No scripts were extracted from this sample, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7090092094097097/La-face-crash-e-de-Marine-Le-Pen-by-Richard-Malka.pdf
    • http://loaminoo.linkpc.net/8094095098092095/Ayrton-Senna-Christ-in-a-Crash-Helmet-by-Richard-Craig.pdf
    • http://loaminoo.linkpc.net/4097096094097097/Inside-Marine-One-Four-U-S-Presidents-One-Proud-Marine-and-the-World-s-Most-Amazing-Helicopter-by-Ray-L-39-Heureux.pdf
    • http://loaminoo.linkpc.net/1092090096091099/The-Man-With-The-Getaway-Face-Parker-2-by-Richard-Stark.pdf
    • http://loaminoo.linkpc.net/4092093094098099/The-Hidden-Face-of-God-by-Richard-Elliott-Friedman.pdf
    • http://loaminoo.linkpc.net/3098090095090094/Barbarians-of-Malka-Barbarians-of-Malka-5-by-Justus-Roux.pdf
    • http://loaminoo.linkpc.net/2092095090096099/A-Candle-for-a-Marine-Always-a-Marine-18-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/3099096093092097/Marine-With-Benefits-Always-a-Marine-16-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/7090092095093092/Sukkot-A-Time-to-Rejoice-A-Jewish-Holidays-Book-Drucker-Malka-Jewish-Holidays-Book-by-Malka-Drucker.pdf
    • http://loaminoo.linkpc.net/6098094099093099/Warfighting-Marine-Corps-Doctrinal-Publication-1-by-U-S-Marine-Corps.pdf
    • http://loaminoo.linkpc.net/2097091090099098/Face-to-Face-with-God-Transform-Your-Life-with-His-Daily-Presence-by-Bill-Johnson.pdf
    • http://loaminoo.linkpc.net/1094099092093096/A-Crime-So-Monstrous-Face-to-Face-with-Modern-Day-Slavery-by-E-Benjamin-Skinner.pdf
    • http://loaminoo.linkpc.net/2097091090097099/This-Was-Your-Life-Preparing-to-Meet-God-Face-to-Face-by-Rick-Howard.pdf
    • http://loaminoo.linkpc.net/7096096093099099/Un-d-sir-indomptable---Troublant-face---face-by-Julia-James.pdf
    • http://loaminoo.linkpc.net/1091098094097099090/The-Nazis---Through-the-Eyes-of-a-Child-The-autobiography-of-a-young-Jewish-refugee-who-came-face-to-face-with-Hitler-by-Margarete-Mendelsohn.pdf
    • http://loaminoo.linkpc.net/1090098090091099090/Lotte-Lasersteing-Face-to-Face-by-Alexander-Eiling.pdf
    • http://loaminoo.linkpc.net/5092094099090097/Les-Effac-s---Tome-4---Face-face-by-Bertrand-Puard.pdf
    • http://loaminoo.linkpc.net/1091094097091096099/Bad-Company-Face-to-Face-with-the-Taliban-by-Chantelle-Taylor.pdf
    • http://loaminoo.linkpc.net/8095093094091097/Face-to-Face-With-Elephants-by-Dereck-Joubert.pdf
    • http://loaminoo.linkpc.net/7094097094091096/Face-to-Face-Hart-and-Drake-3-by-C-J-Lyons.pdf
    • http://loaminoo.linkpc.net/7090092095093092/Sukkot-A-Time-to-Rejoice-A-Jewish-Holidays-Book-Drucker-Ma