Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4050bfdad327146…

MALICIOUS

PDF

15.8 KB Created: 2019-05-02 03:26:41 +01:00 Authoring application: mPDF 5.7
MD5: c7d85aafea334b8f25b296e80422bebb SHA-1: 373a92df4469be981978d2d7a90e6575854b866c SHA-256: c4050bfdad327146c8d433718c52a03d014876905e495e4a9049df3b88cc219d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF_SEO_LINK_FARM heuristic indicates a large number of embedded links, suggesting a link farm or redirection scheme. The ML_NYX_PDF_MALICIOUS classifier also flagged this document with high confidence. While no scripts were extracted, the presence of numerous external links, many pointing to loaminoo.linkpc.net, strongly suggests a phishing or malicious content delivery attempt. The document body contains these URLs, reinforcing the attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9880

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5096098098096097/Opposites-Attract-A-Haiku-Tete-A-Tete-by-Mary-Braun.pdf
    • http://loaminoo.linkpc.net/5096098099096094/Tete-A-Tete-with-Muhammad-by-Husam-Dughman.pdf
    • http://loaminoo.linkpc.net/5092098093094096/T-te-T-te-by-Henri-Cartier-Bresson.pdf
    • http://loaminoo.linkpc.net/5096098098096091/Democratisation-a-la-Togolaise-by-Tete-Tete.pdf
    • http://loaminoo.linkpc.net/9096092090094092/Wenn-Hexen-Vampire-bei-Vollmond-k-ssen-ist-der-Werwolf-sauer-by-Mia-Dako.pdf
    • http://loaminoo.linkpc.net/9096092090099098/Wenn-Hexen-Vampire-bei-Vollmond-k-ssen-ist-der-Werwolf-sauer-Gesamtausgabe-B-nde-1---3-by-Mia-Dako.pdf
    • http://loaminoo.linkpc.net/6090095095098093/Albania-s-Rights-and-Claims-to-Independance-and-Territorial-Integrity---Scholar-s-Choice-Edition-by-Christo-Anastas-1878--From-Old-Dako.pdf
    • http://loaminoo.linkpc.net/8092091097091090/Le-Cheval-Sans-Tete-by-Berna.pdf
    • http://loaminoo.linkpc.net/5094090096093098/Tenir-t-te-aux-dieux-by-Mahmoud-Hussein.pdf
    • http://loaminoo.linkpc.net/4098099093097091/Tete-Blanche-by-Marie-Claire-Blais.pdf
    • http://loaminoo.linkpc.net/8094094091094091/THE-ZOMBIE-THAT-ATE-THE-WORLD-T-01-RAMENEZ-MOI-MA-T-TE-by-Jerry-Frissen.pdf
    • http://loaminoo.linkpc.net/5096099090091095/Garder-la-t-te-hors-de-l-eau-Une-enfance-au-Chelsea-Hotel-by-Nicolaia-Rips.pdf
    • http://loaminoo.linkpc.net/2099099097097090/One-Last-Try-by-Kari-Gregg.pdf
    • http://loaminoo.linkpc.net/3098094094098098/Lentolaivue-24-by-Kari-Stenman.pdf
    • http://loaminoo.linkpc.net/3090090096092091/You-Melted-Me-by-Kari-Gregg.pdf
    • http://loaminoo.linkpc.net/3097099097092092/So-Much-for-Democracy-by-Kari-Jones.pdf
    • http://loaminoo.linkpc.net/1094094097098098/Hunt-the-Moon-by-Kari-Cole.pdf
    • http://loaminoo.linkpc.net/2095096095095093/Pretty-Poison-by-Kari-Gregg.pdf
    • http://loaminoo.linkpc.net/4090094093095099/Under-a-Shifter-s-Moon-by-Kari-Thomas.pdf
    • http://loaminoo.linkpc.net/3098092098097095/Plunder-Spoils-of-War-2-by-Kari-Gregg.pdf