Malicious PDF — malware analysis report

Static analysis result for SHA-256 732076fa7be74f0f…

MALICIOUS

PDF

14.8 KB Created: 2019-04-30 18:48:12 +01:00 Authoring application: mPDF 5.7
MD5: 958760c9a142629bf8685e1bcc7a7b8d SHA-1: afb0a00e6aed063f3e082ab461b0ade53cc79bf0 SHA-256: 732076fa7be74f0f5665ce738e355e076bce42c51fc66143ca54151dafe2fbbe
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files hosted on the 'loaminoo.linkpc.net' domain. This heuristic, combined with the ML classifier, indicates a malicious intent, likely to manipulate search engine results or distribute further content. While no scripts were extracted, the presence of numerous external links suggests a potential for further malicious activity or a link farm for SEO poisoning.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9891

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1094095095091092/Love-Lies-amp-High-Heels-Love-Lies-and-More-Lies-1-by-Debby-Conrad.pdf
    • http://loaminoo.linkpc.net/3090093095095092/The-Emperor-of-Lies-by-Steve-Sem-Sandberg.pdf
    • http://loaminoo.linkpc.net/5096098091094092/Guardian-of-Lies-Paul-Madriani-10-by-Steve-Martini.pdf
    • http://loaminoo.linkpc.net/1093095090/Love-Lies-Beneath-Love-Lies-Beneath-1-by-Ellen-Hopkins.pdf
    • http://loaminoo.linkpc.net/2097096097095098/Lies-Ripped-Open-Hellequin-Chronicles-5-by-Steve-McHugh.pdf
    • http://loaminoo.linkpc.net/1090091090091090/American-Conspiracies-Lies-Lies-and-More-Dirty-Lies-that-the-Government-Tells-Us-by-Jesse-Ventura.pdf
    • http://loaminoo.linkpc.net/1096092098093093/Dying-For-Love-by-Morgan-James.pdf
    • http://loaminoo.linkpc.net/4093097094098091/TwoWorlds-The-Art-of-Dying-Love-by-R-B-Anderson.pdf
    • http://loaminoo.linkpc.net/9099094095093096/Testaments-Poems-of-Love-amp-Betrayal-Desire-amp-Dying-by-Sol-Erebos.pdf
    • http://loaminoo.linkpc.net/1092094099095090/THE-CATHOLIC-WOMAN-S-DYING-WISH-A-bittersweet-love-story-by-Joanna-Warrington.pdf
    • http://loaminoo.linkpc.net/1095095090091095/Here-Lies-Love-by-Dan-C-Thompson.pdf
    • http://loaminoo.linkpc.net/5094098094098095/Where-Love-Lies-by-Julie-Cohen.pdf
    • http://loaminoo.linkpc.net/7090099099092093/Love-Lies-by-MaryJanice-Davidson.pdf
    • http://loaminoo.linkpc.net/4096098091092097/Love-Lies-and-Deception-by-L-P-Dover.pdf
    • http://loaminoo.linkpc.net/5093096090092091/Love-Lies-Karma-2-by-Kiera-Thomas.pdf
    • http://loaminoo.linkpc.net/3098096094090098/Love-Lies-and-Murder-by-Shiloh-Walker.pdf
    • http://loaminoo.linkpc.net/3094094097096/Dirty-Red-Love-Me-with-Lies-2-by-Tarryn-Fisher.pdf
    • http://loaminoo.linkpc.net/3092090099094095/The-Love-amp-Lies-of-Rukhsana-Ali-by-Sabina-Khan.pdf
    • http://loaminoo.linkpc.net/3095097094098095/Love-Lies-Beneath-by-Ellen-Hopkins.pdf
    • http://loaminoo.linkpc.net/1094095090098090/Never-Let-Me-Go-Secrets-And-Lies-Book-2-by-Roxy-Love.pdf