Malicious PDF — malware analysis report

Static analysis result for SHA-256 43e614c19a7ff981…

MALICIOUS

PDF

22.8 KB Created: 2019-05-04 14:42:17 +01:00 Authoring application: mPDF 5.7
MD5: d560929bf1097507d7b97123d8ad23a4 SHA-1: 0d2d3847e90ff1b0b3d6d00d425138e2319c720b SHA-256: 43e614c19a7ff981453299a3d14a4bfdd9fac371e953613dea60581e913d9cc0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and contains a large number of embedded links, identified as a PDF_SEO_LINK_FARM. The links point to various book titles hosted on loaminoo.linkpc.net. While the individual links are marked as benign, the sheer volume and the heuristic firing suggest a malicious intent, likely for SEO manipulation or to distribute further payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9901

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090091096095095/Ten-Poems-to-Open-Your-Heart-by-Roger-Housden.pdf
    • http://loaminoo.linkpc.net/4095099097094097/All-the-Best-The-Selected-Poems-Of-Roger-Mc-Gough-by-Roger-McGough.pdf
    • http://loaminoo.linkpc.net/4091094099090099/Change-Your-Questions-Change-Your-Life-10-Powerful-Tools-for-Life-and-Work-by-Marilee-G-Adams.pdf
    • http://loaminoo.linkpc.net/4097090092091099/Change-Your-Questions-Change-Your-Life-10-Powerful-Tools-for-Life-and-Work-by-Marilee-G-Adams.pdf
    • http://loaminoo.linkpc.net/3092091091091098/The-Book-of-Life-Change-Your-Mind-and-Change-Your-Life-by-Jo-Rodrigues.pdf
    • http://loaminoo.linkpc.net/7098094098096/How-Successful-People-Think-Change-Your-Thinking-Change-Your-Life-by-John-C-Maxwell.pdf
    • http://loaminoo.linkpc.net/9092097093094097/The-Lose-Your-Belly-Diet-Change-Your-Gut-Change-Your-Life-by-Travis-Stork.pdf
    • http://loaminoo.linkpc.net/9096097093096/Designer-Mindset-Change-your-mind-Change-your-life-by-Gina-Carr-.pdf
    • http://loaminoo.linkpc.net/6090099094090096/Change-Your-Words-Change-Your-Life-Understanding-the-Power-of-Every-Word-You-Speak-by-Joyce-Meyer.pdf
    • http://loaminoo.linkpc.net/1095096097091093/You-Are-WHY-You-Eat-Change-Your-Food-Attitude-Change-Your-Life-by-Ramani-Durvasula.pdf
    • http://loaminoo.linkpc.net/5091092099099/Letters-from-Siberia-and-Other-Poems-by-Roger-Mitchell.pdf
    • http://loaminoo.linkpc.net/4098093095091/Sea-Change-Poems-by-Christopher-Howell.pdf
    • http://loaminoo.linkpc.net/5092097096094092/The-Kingfisher-Book-of-Funny-Poems-by-Roger-McGough.pdf
    • http://loaminoo.linkpc.net/1092093098096090/Fortune-is-a-River-Leonardo-da-Vinci-and-Niccolo-Machiavelli-s-Magnificent-Dream-to-Change-the-Course-of-Florentine-History-by-Roger-D-Masters.pdf
    • http://loaminoo.linkpc.net/9096099094094095/Change-up-Baseball-Poems-by-Gene-Fehler.pdf
    • http://loaminoo.linkpc.net/2093090091090092/Get-the-Life-You-Want-The-Secrets-to-Quick-and-Lasting-Life-Change-with-Neuro-Linguistic-Programming-by-Richard-Bandler.pdf
    • http://loaminoo.linkpc.net/2097095097093091/Myths-of-the-Norsemen-Retold-from-the-Old-Norse-Poems-and-Tales-by-Roger-Lancelyn-Green.pdf
    • http://loaminoo.linkpc.net/5097096098094/One-Million-Lovely-Letters-When-Life-is-Looking-Hopeless-One-Inspirational-Letter-Can-Change-Your-Life-Forever-by-Jodi-Ann-Bickley.pdf
    • http://loaminoo.linkpc.net/1091091097097096090/Poems-of-the-Irish-Revolutionary-Brotherhood-Thomas-MacDonagh-P-H-Pearse-Joseph-Mary-Plunkett-Sir-Roger-Casement-1916-by-Padraic-Colum.pdf
    • http://loaminoo.linkpc.net/2092092095098093/Unraveled-The-True-Story-of-a-Woman-Who-Dared-to-Become-a-Different-Kind-of-Mother-by-Maria-Housden.pdf
    • http://loaminoo.linkpc.net/9096097093