Malicious PDF — malware analysis report

Static analysis result for SHA-256 8092270194366ecb…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 09:06:04 +01:00 Authoring application: mPDF 5.7
MD5: c79d5a5be92644f61fcd399ef1b3912a SHA-1: bb656dc95aa19d05e7ddb9f172d96f79ae251c40 SHA-256: 8092270194366ecb88b51cb0962f5b9932c0d3e44d1c0ed8078794759aff04cf
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by an ML classifier as malicious. It contains a large number of embedded links, identified as a PDF_SEO_LINK_FARM heuristic, pointing to various PDF files hosted on loaminoo.linkpc.net. While the listed URLs themselves are marked as confirmed_benign, the sheer volume and pattern suggest a link farm intended to distribute malicious content or lead to phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.l
    • http://loaminoo.linkpc.net/2098098097099099/Avatar-The-Last-Airbender-The-Promise-Part-1-The-Promise-1-by-Gene-Luen-Yang.pdf
    • http://loaminoo.linkpc.net/1090093098098/Avatar-The-Last-Airbender-The-Promise-Part-1-The-Promise-1-by-Gene-Luen-Yang.pdf
    • http://loaminoo.linkpc.net/2094099096091096/Avatar-The-Last-Airbender-The-Search-Avatar-The-Last-Airbender-Library-Edition-2-by-Gene-Luen-Yang.pdf
    • http://loaminoo.linkpc.net/6096093093091/Avatar-The-Last-Airbender-The-Rift-Part-3-The-Rift-3-by-Gene-Luen-Yang.pdf
    • http://loaminoo.linkpc.net/2093093090/Avatar-The-Last-Airbender-Smoke-and-Shadow-Part-2-Smoke-and-Shadow-2-by-Gene-Luen-Yang.pdf
    • http://loaminoo.linkpc.net/2099098094098/Level-Up-by-Gene-Luen-Yang.pdf
    • http://loaminoo.linkpc.net/1094099091092/American-Born-Chinese-by-Gene-Luen-Yang.pdf
    • http://loaminoo.linkpc.net/5099092094092/Avatar-Volume-7-The-Last-Airbender-Avatar-7-by-Michael-Dante-DiMartino.pdf
    • http://loaminoo.linkpc.net/4094094092094/Avatar-Volume-5-The-Last-Airbender-Avatar-5-by-Michael-Dante-DiMartino.pdf
    • http://loaminoo.linkpc.net/1092094098/Broken-Promise-Promise-Falls-1-by-Linwood-Barclay.pdf
    • http://loaminoo.linkpc.net/4099098095090095/A-New-Promise-Caitlin-Promise-Trilogy-3-by-Francine-Pascal.pdf
    • http://loaminoo.linkpc.net/1098098092096094/Promise-Me-Always-Pinky-Promise-Sisterhood-1-by-Christine-Lynxwiler.pdf
    • http://loaminoo.linkpc.net/9095090097098091/How-to-Draw-Avatar-The-Last-Airbender-by-Shane-Johnson.pdf
    • http://loaminoo.linkpc.net/4093094094099097/A-Promise-Given-Promise-2-by-Stormy-Glenn.pdf
    • http://loaminoo.linkpc.net/3090090090096098/The-Promise-Rebel-Promise-1-by-May-McGoldrick.pdf
    • http://loaminoo.linkpc.net/1097099093090095/Promise-Me-Promise-Me-1-by-Tara-Fox-Hall.pdf
    • http://loaminoo.linkpc.net/1094095097098097/The-Promise-The-Promise-1-by-Kate-Benson.pdf
    • http://loaminoo.linkpc.net/7093099092090096/Avatar-The-Last-Airbender---The-Lost-Adventures-by-Bryan-Konietzko.pdf
    • http://loaminoo.linkpc.net/5091094098092092/Odin-s-Promise-Odin-s-Promise-1-by-Sandy-Brehl.pdf
    • http://loaminoo.linkpc.net/1096097097097095/A-Man-s-Promise-by-A-T-Russell.pdf