Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd7877462bba6805…

MALICIOUS

PDF

17.9 KB Created: 2019-04-30 04:33:11 +01:00 Authoring application: mPDF 5.7
MD5: fc02e81b8f703878f25096f29df2e1f9 SHA-1: 9c5a4ac8ef3b37014318a8b28ae56d6119190be1 SHA-256: bd7877462bba6805aab6d4f0aae8d35975c5374cd96acae4519dcb6e2ab9c199
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links to external PDF files hosted on the domain 'loaminoo.linkpc.net'. This heuristic firing, combined with the ML classifier's high confidence, indicates a likely attempt to direct users to potentially malicious content or a link farm. No scripts were extracted from this sample, and the document body was heavily obfuscated, preventing a more detailed analysis of the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7091095099095095/The-Jacobin-Club-of-Marseilles-1790-1794-by-Michael-L-Kennedy.pdf
    • http://loaminoo.linkpc.net/7095094090096098/The-Jacobin-Republic-1792-1794-by-Marc-Bouloiseau.pdf
    • http://loaminoo.linkpc.net/3098095095092098/Glorious-First-Of-June-1794-A-Naval-Battle-and-its-Aftermath-by-Michael-Duffy.pdf
    • http://loaminoo.linkpc.net/2095092097092090/Claimed-Club-Sin-1-by-Stacey-Kennedy.pdf
    • http://loaminoo.linkpc.net/2098098096099097/Tamed-Club-Sin-5-by-Stacey-Kennedy.pdf
    • http://loaminoo.linkpc.net/3095094099090095/Robert-F-Kennedy-Ripples-of-Hope-Kerry-Kennedy-in-Conversation-with-Heads-of-State-Business-Leaders-Influencers-and-Activists-about-Her-Father-s-Impact-on-Their-Lives-by-Kerry-Kennedy.pdf
    • http://loaminoo.linkpc.net/1092099092092091/The-Kennedy-Rifle-Michael-Cole-1-by-J-K-Brandon.pdf
    • http://loaminoo.linkpc.net/7090092099093098/Patrick-Bouvier-Kennedy-by-Michael-S-Ryan-RRT-NPS.pdf
    • http://loaminoo.linkpc.net/4097097096098093/The-Other-Man-John-F-Kennedy-Jr-Carolyn-Bessette-and-Me-by-Michael-Bergin.pdf
    • http://loaminoo.linkpc.net/7091095098095094/Death-Of-A-Marseilles-Man-by-L-o-Malet.pdf
    • http://loaminoo.linkpc.net/7091095098099090/Tarot-of-Marseilles-by-Claude-Burdel.pdf
    • http://loaminoo.linkpc.net/6090091098090094/Toussaint-Louverture-A-Black-Jacobin-in-the-Age-of-Revolutions-Revolutionary-Lives-by-Charles-Forsdick.pdf
    • http://loaminoo.linkpc.net/7091095098097094/World-Film-Locations-Marseilles-by-Marcelline-Block.pdf
    • http://loaminoo.linkpc.net/2096090092094094/Kick-Kennedy-The-Charmed-Life-and-Tragic-Death-of-the-Favorite-Kennedy-Daughter-by-Barbara-Leaming.pdf
    • http://loaminoo.linkpc.net/3093095099098093/Mrs-Kennedy-The-Missing-History-of-the-Kennedy-Years-by-Barbara-Leaming.pdf
    • http://loaminoo.linkpc.net/4091098091095098/The-Travelers-Club-and-the-Ghost-Ship-by-Michael-Bradley.pdf
    • http://loaminoo.linkpc.net/1091094091098099093/The-Treasure-Hunt-Club-by-Michael-Scott-Clifton.pdf
    • http://loaminoo.linkpc.net/8093092098091094/The-Teddy-Bear-Club-The-Teddy-Bear-Club-1-by-Sean-Michael.pdf
    • http://loaminoo.linkpc.net/2093091091094/The-Transformation-of-Virginia-1740-1790-by-Rhys-Isaac.pdf
    • http://loaminoo.linkpc.net/6092093096098096/La-grande-fracture-1790-1793-by-Michel-Winock.pdf
    • http://loaminoo.linkpc.net/4097097096098093/The-Other-Man-