Malicious PDF — malware analysis report

Static analysis result for SHA-256 55477eff687f328c…

MALICIOUS

PDF

18.3 KB Created: 2019-05-01 19:33:57 +01:00 Authoring application: mPDF 5.7
MD5: 0dc17679eab55bf3032a2e5ab8869566 SHA-1: 124662df4b685321cfccf88915f57d6f54838e2d SHA-256: 55477eff687f328c47fa79bca18f73f4338127e8e0a3d940edab8be02f9b4e60
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier as malicious. The critical heuristic 'PDF_SEO_LINK_FARM' indicates the presence of numerous embedded links, with the dominant host being 'loaminoo.linkpc.net'. While the document body is unreadable, the structure suggests a link farm designed to manipulate search results or distribute malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3090090093095094/It-Came-From-The-Far-Side-by-Gary-Larson.pdf
    • http://loaminoo.linkpc.net/2098093098092096/In-Search-of-The-Far-Side-by-Gary-Larson.pdf
    • http://loaminoo.linkpc.net/3090090097097098/The-Bride-Of-The-Far-Side-by-Gary-Larson.pdf
    • http://loaminoo.linkpc.net/2099097093091098/The-Prehistory-Of-The-Far-Side-A-10th-Anniversary-Exhibit-by-Gary-Larson.pdf
    • http://loaminoo.linkpc.net/1097099096095/Side-by-Side-Leadership-Achieving-Outstanding-Results-Together-by-Dennis-A-Romig.pdf
    • http://loaminoo.linkpc.net/5091097099091094/Claiming-Abraham-Reading-the-Bible-and-the-Qur-an-Side-by-Side-by-Michael-E-Lodahl.pdf
    • http://loaminoo.linkpc.net/9093091093090096/Three-Translations-of-the-Koran-Al-Qur-an---Side-by-Side-with-Each-Verse-Not-Split-Across-Pages-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/1091090093098095096/Side-by-Side-The-Revolutionary-Mother-Daughter-Program-for-Conflict-Free-Communication-by-Charles-Sophy.pdf
    • http://loaminoo.linkpc.net/1096090097095092/The-Other-Side-The-Other-Side-Trilogy-Book-1-by-Anna-Marie-McIntyre.pdf
    • http://loaminoo.linkpc.net/1098095094091/Photoshop-Painter-Illustrator-Side-By-Side-by-Wendy-Crumpler.pdf
    • http://loaminoo.linkpc.net/8094090094095/The-Dark-Side-of-Midnight-Featuring-The-Other-Side-of-Midnight-Rage-of-Angels-Bloodline-by-Sidney-Sheldon.pdf
    • http://loaminoo.linkpc.net/2099094090091095/Side-by-Side-by-Jenni-L-Walsh.pdf
    • http://loaminoo.linkpc.net/9099093099098091/On-Bread-amp-Poetry-A-Panel-Discussion-with-Gary-Snyder-Lew-Welch-amp-Philip-Whalen-by-Gary-Snyder.pdf
    • http://loaminoo.linkpc.net/5092092095091090/Permutations-Of-The-Gallery-by-Joshua-McKinney.pdf
    • http://loaminoo.linkpc.net/1091092092094098092/Shooting-Gallery-Dewey-Andreas-8-5-by-Ben-Coes.pdf
    • http://loaminoo.linkpc.net/9090095095093/National-Gallery-of-Art-Washington-by-John-Walker.pdf
    • http://loaminoo.linkpc.net/8098097093091098/The-Triumph-of-Painting-Germania-by-Saatchi-Gallery.pdf
    • http://loaminoo.linkpc.net/1091096092097098099/Gallery-Whispers-Bob-Skinner-9-by-Quintin-Jardine.pdf
    • http://loaminoo.linkpc.net/4098095092/The-Girl-from-the-Other-Side-Si-il-A-R-n-Volume-1-The-Girl-from-the-Other-Side-1-by-Nagabe.pdf
    • http://loaminoo.linkpc.net/3092092092094091/Other-Side-of-Night-Bastian-amp-Riley-Other-Side-of-Night-1-by-S-L-Armstrong.pdf
    • http://loaminoo.linkpc.net/1091090093098095096/Side-by-Side-The-Revolutionary-Mother-Dau