Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e01f11517aec66a…

MALICIOUS

PDF

18.1 KB Created: 2019-05-07 08:28:47 +01:00 Authoring application: mPDF 5.7
MD5: c2225da5dd8648861dd0a0d9f545c2e5 SHA-1: 92224d530254bd0dfb0a3d58d6baf3abfa50a241 SHA-256: 7e01f11517aec66ab14b50c8a2b514e9c156c6f6a296458a7f91b0b08472b3d4
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to book-related content hosted on loaminoo.linkpc.net. While the extracted URLs themselves are marked as benign, the sheer volume and structure suggest a link farm or SEO manipulation tactic. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. The attack pattern is likely a lure to disguise malicious activity or to drive traffic to potentially compromised sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9096098095098/Living-the-Wisdom-of-the-Tao-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/9091092097097/Everyday-Wisdom-Trade-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/9091091096098/Wisdom-of-the-Ages-60-Days-to-Enlightenment-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/5099093091096/Gifts-from-Eykis-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/8090093092092092/Pensees-inspirantes-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/9091093099091/10-Secrets-for-Success-and-Inner-Peace-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/7093091098097092/A-New-Way-of-Thinking-A-New-Way-of-Being-Experiencing-the-Tao-Te-ching-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/3092091090098091/Wishes-Fulfilled-Mastering-the-Art-of-Manifesting-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/5096098094093/The-Shift-Taking-Your-Life-from-Ambition-to-Meaning-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/6091097095091/Being-In-Balance-9-Principles-for-Creating-Habits-to-Match-Your-Desires-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/7091096099097090/La-fuerza-de-creer-You-ll-see-it-when-you-believe-it-C-mo-cambiar-su-vida-The-Way-to-Your-Personal-Transformation-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/1091098091099099095/Excuses-Begone-How-to-Change-Lifelong-Self-Defeating-Thinking-Habits-by-Wayne-W-Dyer.pdf
    • http://loaminoo.linkpc.net/6094090097093096/Sermons-Biblical-Wisdom-For-Daily-Living-by-Peter-J-Gomes.pdf
    • http://loaminoo.linkpc.net/2098090095095095/The-Book-of-Wisecracks-Windows-of-Wisdom-for-Living-Well-by-Gerald-Mann.pdf
    • http://loaminoo.linkpc.net/5095091094099/Resilience-Hard-Won-Wisdom-for-Living-a-Better-Life-by-Eric-Greitens.pdf
    • http://loaminoo.linkpc.net/1096097096090092/Country-Wisdom-amp-Know-How-A-Practical-Guide-to-Living-off-the-Land-by-M-John-Storey.pdf
    • http://loaminoo.linkpc.net/8091090090093096/Radical-Wisdom-Living-from-Silence-while-Rocking-the-World-by-Robert-Rabbin.pdf
    • http://loaminoo.linkpc.net/3096091092093098/A-Year-With-The-Church-Fathers-Patristic-Wisdom-For-Daily-Living-by-Mike-Aquilina.pdf
    • http://loaminoo.linkpc.net/7092099091094090/Love-Centered-Parenting-Contributing-to-Your-Child-s-Wellness-by-Living-from-the-Heart-and-Cultivating-Your-Inner-Wisdom-by-Maria-Gavriel.pdf
    • http://loaminoo.linkpc.net/2099096099098095/John-Wayne-My-Father-by-Aissa-Wayne.pdf
    • http://loaminoo.linkpc.net/7091096099097090/La-fuerza-de-creer-You-ll-see-i