Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d5e704f2467b2e4…

MALICIOUS

PDF

16.7 KB Created: 2019-04-24 22:18:24 +01:00 Authoring application: mPDF 5.7
MD5: 1a3e9bee586bad2f0ef2821eafb7402a SHA-1: 318c246f563e0acd9e0eb2446fa576413e9da453 SHA-256: 7d5e704f2467b2e4b230509aac75e651d9156716e7fb47c74d0086e1bd4e2eed
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF was flagged by a critical heuristic for containing a mass external PDF link farm, with 22 links pointing to the dominant host 'loaminoo.linkpc.net'. While the specific URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or as a distribution vector for further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc
    • http://loaminoo.linkpc.net/6096095096096099/la-derni-re-chose-dont-il-a-besoin-by-J-H-Knight.pdf
    • http://loaminoo.linkpc.net/6096095096096095/Instruments-Entre-Les-Mains-Du-Redempteur-Instruments-in-the-Redeemer-s-Hands-Quand-Dieu-Utilise-Des-Gens-Qui-Ont-Besoin-de-Changement-Pour-En-Aider-D-Autres-Qui-Ont-Besoin-de-Changement-by-Paul-David-Tripp.pdf
    • http://loaminoo.linkpc.net/1090097097099096099/Aisha-Loves-to-Say-Bismillah-by-Meidya-Derni.pdf
    • http://loaminoo.linkpc.net/6096095098096095/J-ai-Besoin-d-un-Miracle-by-D-K-Olukoya.pdf
    • http://loaminoo.linkpc.net/6096095098097095/La-Culture-Un-Besoin-D-Etat-by-Claude-Patriat.pdf
    • http://loaminoo.linkpc.net/6092097097094096/SHOULD-VE-CHOSE-ME-2-by-OCTAVIA-GRANT.pdf
    • http://loaminoo.linkpc.net/2091091099094093/The-Gods-She-Chose-by-Liat-Segal.pdf
    • http://loaminoo.linkpc.net/6092097097095095/I-Chose-To-Climb-by-Chris-Bonington.pdf
    • http://loaminoo.linkpc.net/7092097094099098/La-chose-qui-ne-pouvait-pas-exister-by-Moka.pdf
    • http://loaminoo.linkpc.net/4099099092095/The-Gods-She-Chose-by-Liat-Segal.pdf
    • http://loaminoo.linkpc.net/3097096095096094/I-Chose-Freedom-by-Victor-Kravchenko.pdf
    • http://loaminoo.linkpc.net/3096094099094096/Will-s-Red-Coat-The-Story-of-One-Old-Dog-Who-Chose-to-Live-Again-by-Tom-Ryan.pdf
    • http://loaminoo.linkpc.net/1090096093098090/Daria-Rose-and-the-Day-She-Chose-by-Yvonne-Capitelli.pdf
    • http://loaminoo.linkpc.net/6092097098093098/The-Streets-Chose-Me-An-ATL-Love-Story-by-Myia-White.pdf
    • http://loaminoo.linkpc.net/6090093099097098/Derri-re-toute-chose-exquise-by-S-bastien-Fritsch.pdf
    • http://loaminoo.linkpc.net/6092097098091092/The-Girl-Who-Chose-A-New-Way-Of-Narrating-The-Ramayana-by-Devdutt-Pattanaik.pdf
    • http://loaminoo.linkpc.net/6092097098090097/Why-the-Devil-Chose-New-England-for-His-Work-Stories-by-Jason-Brown.pdf
    • http://loaminoo.linkpc.net/8095097096095098/Dont-Look-Behind-You-and-The-Babysitter-by-Roy-Apps.pdf
    • http://loaminoo.linkpc.net/8095097096099098/MAMA-DONT-ALLOW-by-Hurd.pdf
    • http://loaminoo.linkpc.net/8095097096092090/Dont-Let-Me-Go-by-Catherine-Ryan-Hyde.pdf