Malicious PDF — malware analysis report

Static analysis result for SHA-256 576f76d6dd9147be…

MALICIOUS

PDF

13.9 KB Created: 2019-05-02 05:15:24 +01:00 Authoring application: mPDF 5.7
MD5: b84aba328ed48cb0929835c401b58111 SHA-1: 0043c5df1f1fc8ea85a1acdabe5622747b572343 SHA-256: 576f76d6dd9147be7ce0ae200eff540573e818760701e7802dfa89a1f24fb1af
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF heuristic 'PDF_SEO_LINK_FARM' indicates the presence of a mass external PDF link farm, with the dominant host being 'loaminoo.linkpc.net'. The ML classifier also flagged this PDF as malicious with a high score. The embedded URLs, while many are marked as confirmed benign, are part of a pattern likely intended to manipulate search engine results or redirect users to malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9093092093092092/Locked-amp-Loaded-Ricochet-1-by-Heather-C-Leigh.pdf
    • http://loaminoo.linkpc.net/9093092093099097/All-In-Locked-amp-Loaded-5-by-Susan-Ward.pdf
    • http://loaminoo.linkpc.net/3092098095097095/Locked-and-Loaded-Cougar-Challenge-11-by-Samantha-Cayto.pdf
    • http://loaminoo.linkpc.net/3094095096097093/Killer-by-Heather-C-Leigh.pdf
    • http://loaminoo.linkpc.net/5090093097093096/Jagger-Broken-Doll-2-by-Heather-C-Leigh.pdf
    • http://loaminoo.linkpc.net/2098093092095095/Incite-Adam-Sphere-of-Irony-1-by-Heather-C-Leigh.pdf
    • http://loaminoo.linkpc.net/4093097094097091/Brilliant-Dark-Summer-Snow-Winter-Sun-2-by-Heather-Leigh.pdf
    • http://loaminoo.linkpc.net/2099093093096096/Burning-Desire-Condemned-Angels-Series-1-by-Heather-Leigh.pdf
    • http://loaminoo.linkpc.net/3093099092090092/Absolutely-Famous-Famous-2-by-Heather-C-Leigh.pdf
    • http://loaminoo.linkpc.net/3098093098096090/Absolutely-Famous-Famous-2-by-Heather-C-Leigh.pdf
    • http://loaminoo.linkpc.net/5097093096096/Absolutely-Famous-Famous-2-by-Heather-C-Leigh.pdf
    • http://loaminoo.linkpc.net/5092091092091/Ricochet-by-Keri-Lake.pdf
    • http://loaminoo.linkpc.net/4093099098099094/R-is-for-Ricochet-Kinsey-Millhone-18-by-Sue-Grafton.pdf
    • http://loaminoo.linkpc.net/1091096099096093/R-is-for-Ricochet-Kinsey-Millhone-18-by-Sue-Grafton.pdf
    • http://loaminoo.linkpc.net/3098093098095098/Relatively-Famous-Famous-1-by-Heather-C-Leigh.pdf
    • http://loaminoo.linkpc.net/4092091097092/Relatively-Famous-Famous-1-by-Heather-C-Leigh.pdf
    • http://loaminoo.linkpc.net/1095099093097097/Ricochet-Two-Women-War-Reporters-and-a-Friendship-Under-Fire-by-Mary-Jo-McConahay.pdf
    • http://loaminoo.linkpc.net/5093090098095095/Bases-Loaded-by-F-Leonora-Solomon.pdf
    • http://loaminoo.linkpc.net/3090091097095098/Stepbrother-Loaded-by-Madelin-Brook.pdf
    • http://loaminoo.linkpc.net/1098099098091093/Never-Stand-Behind-a-Loaded-Horse-by-Gordon-Kirkland.pdf
    • http://loaminoo.linkpc.net/1091096099096093/R-is-for-Ricochet-Kin