Malicious PDF — malware analysis report

Static analysis result for SHA-256 d739072ccbafa5ac…

MALICIOUS

PDF

18.9 KB Created: 2019-05-07 03:09:15 +01:00 Authoring application: mPDF 5.7
MD5: f389152a8e8de21d282fdf64502eb5e8 SHA-1: b3eb1fdd076f19c1a2fd3b5e39d077e61f0f2557 SHA-256: d739072ccbafa5ac61ffbdbb48afcaec0908e2a7908868e1fba17851503fb440
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF documents hosted on 'loaminoo.linkpc.net'. While the URLs themselves are marked as confirmed benign, the sheer volume and structure suggest a link farm designed to distribute or obscure malicious content. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.l
    • http://loaminoo.linkpc.net/2093090094096097/Warrior-Queen-The-Story-of-Boudica-Celtic-Queen-by-Alan-Gold.pdf
    • http://loaminoo.linkpc.net/8096096092/The-Warrior-Queen-The-Hundredth-Queen-4-by-Emily-R-King.pdf
    • http://loaminoo.linkpc.net/4090093095095093/Five-Gold-Rings-A-Royal-Wedding-Souvenir-Album-from-Queen-Victoria-to-Queen-Elizabeth-II-by-Jane-Roberts.pdf
    • http://loaminoo.linkpc.net/3096099090099092/Ellery-Queen-s-Japanese-Golden-Dozen-The-Detective-Story-World-in-Japan-by-Ellery-Queen.pdf
    • http://loaminoo.linkpc.net/2093091091090098/Xena-Warrior-Princess-Queen-of-the-Amazons-by-Kerry-Milliron.pdf
    • http://loaminoo.linkpc.net/2093090097094094/Ashes-of-Britannia-Warrior-Queen-3-by-Haley-Elizabeth-Garwood.pdf
    • http://loaminoo.linkpc.net/1096097098093095/For-King-and-Country-The-Saga-of-Thistles-and-Roses-The-Warrior-Queen-1-by-Karen-Gray.pdf
    • http://loaminoo.linkpc.net/1097098097097093/Counting-One-s-Blessings-The-Selected-Letters-of-Queen-Elizabeth-the-Queen-Mother-by-William-Shawcross.pdf
    • http://loaminoo.linkpc.net/4097096098095095/The-Lady-Queen-The-Notorious-Reign-of-Joanna-I-Queen-of-Naples-Jerusalem-and-Sicily-by-Nancy-Goldstone.pdf
    • http://loaminoo.linkpc.net/2094099093090/The-Summer-Queen-The-Snow-Queen-Cycle-3-by-Joan-D-Vinge.pdf
    • http://loaminoo.linkpc.net/1095090099091090/Queen-s-Own-Fool-A-Novel-of-Mary-Queen-of-Scots-by-Jane-Yolen.pdf
    • http://loaminoo.linkpc.net/2094092097091099/The-Queen-of-Attolia-The-Queen-s-Thief-2-by-Megan-Whalen-Turner.pdf
    • http://loaminoo.linkpc.net/1090094095090097/The-Unruly-Queen-The-Life-of-Queen-Caroline-by-Flora-Fraser.pdf
    • http://loaminoo.linkpc.net/3094092096093092/The-Idylls-of-the-Queen-A-Tale-of-Queen-Guenevere-by-Phyllis-Ann-Karr.pdf
    • http://loaminoo.linkpc.net/2091090092090091/Queen-Takes-Knights-Their-Vampire-Queen-1-by-Joely-Sue-Burkhart.pdf
    • http://loaminoo.linkpc.net/2092092099093092/The-True-Queen-The-Impostor-Queen-3-by-Sarah-Fine.pdf
    • http://loaminoo.linkpc.net/7099096091/Daughters-of-the-Winter-Queen-Four-Remarkable-Sisters-the-Crown-of-Bohemia-and-the-Enduring-Legacy-of-Mary-Queen-of-Scots-by-Nancy-Goldstone.pdf
    • http://loaminoo.linkpc.net/3095097096099096/Confessions-of-a-Queen-B-The-Queen-B-1-by-Crista-McHugh.pdf
    • http://loaminoo.linkpc.net/1093091099090096/Red-Queen-Red-Queen-1-by-Victoria-Aveyard.pdf
    • http://loaminoo.linkpc.net/2090092/Red-Queen-Red-Queen-1-by-Victoria-Aveyard.pdf