Malicious PDF — malware analysis report

Static analysis result for SHA-256 6a1e06a71f9a1099…

MALICIOUS

PDF

22.2 KB Created: 2019-05-02 05:03:54 +01:00 Authoring application: mPDF 5.7
MD5: aed9834e25444aa4ecece7a7f81aff57 SHA-1: 1adcaf3a7e86f7f78cbc595ea6e9fd72abfe94a3 SHA-256: 6a1e06a71f9a1099b6c038df47d78e4b1aa7a981aee9835ddff7fdf25e8b883f
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a mass external link farm with 27 links, all pointing to PDFs hosted on the 'loaminoo.linkpc.net' domain. This heuristic strongly suggests a malicious intent, likely SEO poisoning or a distribution point for further malware. While no scripts were explicitly extracted, the nature of the link farm and the ML classifier's high confidence indicate a malicious document, potentially delivered via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9903

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1095090095094091/The-Hero-Of-Hastings-The-Knight-Who-Saved-The-Life-of-The-Future-King-of-England-The-deFer-Family-History-Book-1-by-David-Ferrers.pdf
    • http://loaminoo.linkpc.net/2095090099096097/Malicious-History-An-Investigation-Into-King-James-VI-of-Scotland-I-of-England-and-His-Place-in-the-History-of-Witch-Hunts-by-Joe-Kasti.pdf
    • http://loaminoo.linkpc.net/7091099093095091/Letter-from-Alabama-The-Inspiring-True-Story-of-Strangers-Who-Saved-a-Child-and-Changed-a-Family-Forever-by-David-L-Workman.pdf
    • http://loaminoo.linkpc.net/3097090092092091/How-Literature-Saved-My-Life-by-David-Shields.pdf
    • http://loaminoo.linkpc.net/3094095097090098/The-Achievers-A-Personal-Success-Handbook-by-David-Ferrers.pdf
    • http://loaminoo.linkpc.net/6099091094098097/King-Lucius-of-Britain-by-David-J-Knight.pdf
    • http://loaminoo.linkpc.net/4092094097090098/King-of-the-World-Muhammed-Ali-and-the-Rise-of-an-American-Hero-by-David-Remnick.pdf
    • http://loaminoo.linkpc.net/7090097093098095/The-Fears-of-Henry-IV-The-Life-of-England-s-Self-made-King-by-Ian-Mortimer.pdf
    • http://loaminoo.linkpc.net/9/The-War-that-Saved-My-Life-The-War-That-Saved-My-Life-1-by-Kimberly-Brubaker-Bradley.pdf
    • http://loaminoo.linkpc.net/6098092092096098/THE-BEST-HISTORY-4-in-1-HISTORY-OF-ASIA-HISTORY-OF-chaina-HISTORY-OF-COMMUNISM-HISTORY-OF-ENGLAND-by-Good-thailand.pdf
    • http://loaminoo.linkpc.net/6094096092094095/Saved-Part-Two-The-Saved-Series-Book-2-by-Lexi-Larue.pdf
    • http://loaminoo.linkpc.net/5095090093092/First-Family-Sean-King-amp-Michelle-Maxwell-4-by-David-Baldacci.pdf
    • http://loaminoo.linkpc.net/1093092099095098/First-Family-Sean-King-amp-Michelle-Maxwell-4-by-David-Baldacci.pdf
    • http://loaminoo.linkpc.net/3090093095098090/Neal-Cassady-The-Fast-Life-of-a-Beat-Hero-by-David-Sandison.pdf
    • http://loaminoo.linkpc.net/2099094095099/Hero-of-Beecher-Island-The-Life-and-Military-Career-of-George-A-Forsyth-by-David-Dixon.pdf
    • http://loaminoo.linkpc.net/1091090093092099098/The-Swoop-or-How-Clarence-Saved-England-A-Tale-of-the-Great-Invasion-by-P-G-Wodehouse.pdf
    • http://loaminoo.linkpc.net/5091096097093092/Birth-Marriage-and-Death-Ritual-Religion-and-the-Life-Cycle-in-Tudor-and-Stuart-England-by-David-Cressy.pdf
    • http://loaminoo.linkpc.net/2099092092099/Peg-Leg-The-Improbable-Life-of-a-Texas-Hero-Thomas-William-Ward-1807-1872-by-David-C-Humphrey.pdf
    • http://loaminoo.linkpc.net/4097097091098096/Elizabeth-s-Spymaster-Francis-Walsingham-and-the-Secret-War-That-Saved-England-by-Robert-Hutchinson.pdf
    • http://loaminoo.linkpc.net/2091095095099093/England-my-England-by-King-Henry.pdf