Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5f9f7cb62b56d14…

MALICIOUS

PDF

16.8 KB Created: 2019-05-02 00:44:01 +01:00 Authoring application: mPDF 5.7
MD5: 0ec63cfc2aaabd06bf83fc17ad828a4d SHA-1: c6e6ca1603eac4e742482021771230e13a2bac4a SHA-256: e5f9f7cb62b56d140bfa247703dde9bee3a282abc8d1fb7d5ad55f817e26def8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links, indicating a potential SEO spam or malware distribution campaign. The heuristic PDF_SEO_LINK_FARM specifically identifies this pattern, with the dominant host being loaminoo.linkpc.net. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092099099091098/The-13th-by-John-Everson.pdf
    • http://loaminoo.linkpc.net/3098095098091/NightWhere-by-John-Everson.pdf
    • http://loaminoo.linkpc.net/9099097097091096/Deadly-Nightlusts-by-John-Everson.pdf
    • http://loaminoo.linkpc.net/7097099096099098/Vigilantes-of-Love-by-John-Everson.pdf
    • http://loaminoo.linkpc.net/9099097097093095/The-Crawling-Abattoir-by-John-Everson.pdf
    • http://loaminoo.linkpc.net/9099097096094097/Cage-of-Bones-amp-Other-Deadly-Obsessions-by-John-Everson.pdf
    • http://loaminoo.linkpc.net/3091095090097090/Cage-of-Bones-amp-Other-Deadly-Obsessions-by-John-Everson.pdf
    • http://loaminoo.linkpc.net/9093094096093097/Field-of-Flesh-A-NightWhere-Novelette-by-John-Everson.pdf
    • http://loaminoo.linkpc.net/9099097097092091/Cory-Everson-s-Life-Balance-by-Cory-Everson.pdf
    • http://loaminoo.linkpc.net/3094099097095092/Redemption-Road-by-John-Hart.pdf
    • http://loaminoo.linkpc.net/8090090095090092/Redemption-Accomplished-and-Applied-by-John-Murray.pdf
    • http://loaminoo.linkpc.net/3092091092094091/Alien-Redemption-Clans-of-Kalquor-6-by-Tracy-St-John.pdf
    • http://loaminoo.linkpc.net/7092091097093097/Perc-e-nue-8-R-demption-Huiti-me-partie-R-demption-by-Scarlett-Edwards.pdf
    • http://loaminoo.linkpc.net/8090090094096099/Redemption-s-Edge-Redemption-Mountain-1-by-Shirleen-Davies.pdf
    • http://loaminoo.linkpc.net/3097096092091099/Redemption-Ransom-Retribution-Redemption-1-3-by-R-K-Ryals.pdf
    • http://loaminoo.linkpc.net/6094098097093099/-Mi-golah-li-geM--ulah-From-Exile-to-Redemption-Volume-1-Chassidic-teachings-of-the-Lubavitcher-Rebbe-Rabbi-Menachem-M-Schneerson-and-the-preceding-Rebbeim-of-Chab-ad-on-the-future-redemption-and-the-coming-of-Mashiach-by-Eliyahu-Friedman.pdf
    • http://loaminoo.linkpc.net/4094098096091/Redemption-Redemption-1-by-Karen-Kingsbury.pdf
    • http://loaminoo.linkpc.net/2091098099091093/Redemption-Redemption-1-by-Lindsey-Gray.pdf
    • http://loaminoo.linkpc.net/6090092098097091/At-Last-Redemption-Thriller-6-Alex-Troutt-Thriller-6-by-John-W-Mefford.pdf
    • http://loaminoo.linkpc.net/3092093093095093/At-Bay-Redemption-Thriller-1-Alex-Troutt-Thriller-1-by-John-W-Mefford.pdf
    • http://loaminoo.linkpc.net/7092091097093097/Perc-e-nue-8-R-demption-Huiti-me-partie-R-demption-by-Scarlett-Edwa