Malicious PDF — malware analysis report

Static analysis result for SHA-256 553116a346c3756d…

MALICIOUS

PDF

19.0 KB Created: 2019-04-28 05:49:54 +01:00 Authoring application: mPDF 5.7
MD5: c2d29a44022fcea8e8bed910498c3ee4 SHA-1: 663d86b8489936ac8ae16c44f530180a98bdceb3 SHA-256: 553116a346c3756ddd75a097ae13b1d0faad63fc95d7e1a777dab3482849c108
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely for SEO manipulation or to serve as a distribution point for further malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.n
    • http://loaminoo.linkpc.net/4095099092099094/Crazy-Sexy-Love-Rescued-Hearts-3-by-Edie-Ramer.pdf
    • http://loaminoo.linkpc.net/8098094098091098/Crazy-Sexy-Love-Dive-Bar-1-by-Kylie-Scott.pdf
    • http://loaminoo.linkpc.net/3095094097092095/Crazy-Sexy-Love-Dirty-Dicks-1-by-K-L-Grayson.pdf
    • http://loaminoo.linkpc.net/2098096093094099/Rescued-Rescued-Hearts-1-by-Felice-Stevens.pdf
    • http://loaminoo.linkpc.net/7096095097092096/Stardust-Miracle-Miracle-Interrupted-2-by-Edie-Ramer.pdf
    • http://loaminoo.linkpc.net/1091091094091097093/The-Cuckold-Surrender-Hotwife-Femdom-Interracial-Cuckold-Erotica-with-a-sexy-wife-who-s-crazy-for-BBC-and-will-do-anything-for-a-sexy-black-African-dominant-to-be-her-stud-by-Ronnie-Kinski.pdf
    • http://loaminoo.linkpc.net/1094094099092099/Some-Sort-of-Crazy-Happy-Crazy-Love-2-by-Melanie-Harlow.pdf
    • http://loaminoo.linkpc.net/3092096095096098/Crazy-For-The-Cowboy-Love-at-the-Crazy-H-2-by-Cindy-Spencer-Pape.pdf
    • http://loaminoo.linkpc.net/2092095095095096/Kissing-Her-Crazy-Crazy-Love-2-by-Kira-Archer.pdf
    • http://loaminoo.linkpc.net/2098095098099/The-Cancer-Club-A-Crazy-Sexy-Inspirational-Novel-of-Survival-by-Lucinda-Sue-Crosby.pdf
    • http://loaminoo.linkpc.net/1091092095097095090/Crazy-Crazy-Ella-in-Love-1-by-Eve-Langlais.pdf
    • http://loaminoo.linkpc.net/4098093092093097/Scary-Lovesick-Foolish-A-Halloween-Romance-Crazy-Sexy-Ghoulish-Book-2-by-G-G-Andrew.pdf
    • http://loaminoo.linkpc.net/2090092095091095/Wild-Crazy-Hearts-The-Bradens-amp-Montgomerys-Pleasant-Hill---Oak-Falls-4-by-Melissa-Foster.pdf
    • http://loaminoo.linkpc.net/1099096091098096/A-Chance-To-Love-You-AMBW-Sexy-Geek-Series-Book-2-by-Love-Journey.pdf
    • http://loaminoo.linkpc.net/4097090095091097/A-Crazy-Little-Thing-Called-Love-Serendipitous-Love-1-by-Christina-C-Jones.pdf
    • http://loaminoo.linkpc.net/4098099099095098/Animal-Camp-Lessons-in-Love-and-Hope-from-Rescued-Farm-Animals-by-Kathy-Stevens.pdf
    • http://loaminoo.linkpc.net/3093091096097098/Crazy-Kinky-Dirty-Love---Box-Set-Crazy-Kinky-Dirty-Love-1-5-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/3093092091095099/Crazy-Kinky-Dirty-Clowns-Crazy-Kinky-Dirty-Love-4-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/3093092091095091/Crazy-Kinky-Dirty-Stud-Crazy-Kinky-Dirty-Love-2-by-K-A-Merikan.pdf
    • http://loaminoo.linkpc.net/2096099095090093/Crazy-Is-My-Superpower-How-I-Triumphed-by-Breaking-Bones-Breaking-Hearts-and-Breaking-the-Rules-by-A-J-Mendez-Brooks.pdf