Malicious PDF — malware analysis report

Static analysis result for SHA-256 e64f1b85c34a3bfe…

MALICIOUS

PDF

18.7 KB Created: 2019-05-02 05:09:40 +01:00 Authoring application: mPDF 5.7
MD5: db30730a5161fde8b006fac40826a91c SHA-1: 5381961fb664242c0ec72b9b7b1ef5122e0f5b59 SHA-256: e64f1b85c34a3bfeb9fe3fb0ca9e32effab1498f8052de995a9283fe64611598
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, all hosted on the domain 'loaminoo.linkpc.net'. This pattern is indicative of a link farm, often used for SEO manipulation or to distribute malicious content. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests a malicious intent to redirect users to potentially harmful resources. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5098099096090099/A-Cabana-do-Pai-Tom-s-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/6091099099090096/Uncle-Tom-s-Cabin-Or-Life-Among-the-Lowly-1852-by-Harriet-Beecher-Stowe-The-REV-James-Sherman-21-February-1796---15-February-1862-Was-an-English-Congregationalist-Minister-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091092090097098096/Life-Of-Harriet-Beecher-Stowe-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1090095096092093098/Harriet-Beecher-Stowe---Uncle-Tom-s-Cabin-quot-We-First-Make-Our-Habits-Then-Our-Habits-Make-Us-quot-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5097090093098095/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091093098093099098/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1090093090095093096/Agnes-of-Sorrento-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/3095093095098097/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/7090094098091099/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091097093091098096/Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/2097093097098099/Pink-and-White-Tyranny-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091091090092095095/De-hut-van-oom-Tom-Een-verhaal-uit-het-slavenleven-in-Noord-Amerika-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091092090098094096/A-Picture-Book-of-Harriet-Beecher-Stowe-by-David-A-Adler.pdf
    • http://loaminoo.linkpc.net/8095097092098099/Pink-and-White-Tyranny-a-Society-Novel-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/4095090094090/Harriet-Beecher-Stowe-A-Spiritual-Life-by-Nancy-Koester.pdf
    • http://loaminoo.linkpc.net/5092097099099095/Uncle-Tom-s-Cabin-or-Life-among-the-Lowly-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1090098092090093095/Onkel-Toms-H-tte-Uncle-Tom-s-Cabin-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091092090098095094/The-Pearl-of-Orr-s-Island-A-Story-of-the-Coast-of-Maine-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/5098098091090093/Uncle-Tom-s-Cabin-The-Original-Classics---Illustrated-by-Harriet-Beecher-Stowe.pdf
    • http://loaminoo.linkpc.net/1091092090099091096/Harriet-Beecher-Stowe-Connecticut-Girl-by-Mabel-Cleland-Widdemer.pdf