Malicious PDF — malware analysis report

Static analysis result for SHA-256 242cbdf7253f0b1e…

MALICIOUS

PDF

16.0 KB Created: 2019-05-02 01:28:59 +01:00 Authoring application: mPDF 5.7
MD5: 372f50ccedefc79ba78d5b64a205445e SHA-1: 90d5c819686f4227fdcd73c850a8137561522cf0 SHA-256: 242cbdf7253f0b1e28b73389831e4ff05b43054f166b0ca5cbc3ac00f23da367
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by an ML classifier as malicious and contains a large number of external links, many of which point to the same domain, loaminoo.linkpc.net. This indicates a link farm or redirection strategy, likely intended to lead users to malicious content or phishing sites. No scripts were extracted, and the document body was heavily corrupted, preventing a deeper analysis of the immediate user-facing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3097097097095091/In-the-Unlikely-Event-by-Saxon-Bennett.pdf
    • http://loaminoo.linkpc.net/3097098098096091/Sweet-Fire-by-Saxon-Bennett.pdf
    • http://loaminoo.linkpc.net/1091097090099092093/Leofwine-the-Monk-Or-the-Curse-of-the-Ericsons-a-Story-of-a-Saxon-Family-by-Emma-Leslie.pdf
    • http://loaminoo.linkpc.net/2090097094098091/The-Family-Affair-by-Zoe-Jasmine.pdf
    • http://loaminoo.linkpc.net/5099091092091099/A-Family-Affair-by-Agnes-Jaoui.pdf
    • http://loaminoo.linkpc.net/7092094095096091/A-Family-Affair-by-Fern-Michaels.pdf
    • http://loaminoo.linkpc.net/3094095092091090/A-Family-Affair-Truth-in-Lies-1-by-Mary-Campisi.pdf
    • http://loaminoo.linkpc.net/2093091099099099/Family-Affair-Nero-Wolfe-Mystery-by-Rex-Stout.pdf
    • http://loaminoo.linkpc.net/1090099096097096097/The-All-New-Tenchi-Muyo-Vol-9-Family-Affair-by-Hitoshi-Okuda.pdf
    • http://loaminoo.linkpc.net/5095093094099091/Your-One-True-Love-The-Bennett-Family-8-by-Layla-Hagen.pdf
    • http://loaminoo.linkpc.net/2091097092098099/Wife-For-a-Week-Bennett-Family-1-by-Kelly-Hunter.pdf
    • http://loaminoo.linkpc.net/4099090090094091/The-Affair-of-the-39-Cufflinks-Burford-Family-Mysteries-3-by-James-Anderson.pdf
    • http://loaminoo.linkpc.net/8095096090098099/Adoption-is-a-Family-Affair-What-Relatives-and-Friends-Must-Know-by-Patricia-Irwin-Johnston.pdf
    • http://loaminoo.linkpc.net/4096099098099092/The-Affair-of-the-Bloodstained-Egg-Cosy-Burford-Family-Mysteries-1-by-James-Anderson.pdf
    • http://loaminoo.linkpc.net/4096099096098094/The-Affair-of-the-Thirty-Nine-Cufflinks-Burford-Family-Mysteries-3-by-James-Anderson.pdf
    • http://loaminoo.linkpc.net/4098096099094095/Merry-Mitchell-Affair-The-Mitchell-Healy-Family-3-5-by-Jennifer-Foor.pdf
    • http://loaminoo.linkpc.net/9093099090099091/The-President-s-Affair-A-Dramatization-of-the-Clinton-Lewinsky-Affair-by-John-Gordon-Gray.pdf
    • http://loaminoo.linkpc.net/1090097094093098093/Bewulf-an-Anglo-Saxon-Poem-the-Fight-at-Finnsburh-a-Fragmbewulf-an-Anglo-Saxon-Poem-the-Fight-at-Finnsburh-a-Fragment-with-Text-and-Glossary-on-by-Moriz-Heyne.pdf
    • http://loaminoo.linkpc.net/9091096095096096/John-G-Bennett-s-Talks-on-Beelzebub-s-Tales-by-J-G-Bennett.pdf
    • http://loaminoo.linkpc.net/4097094094094090/Outback-Affair-Affair-3-by-Annie-Seaton.pdf