Malicious PDF — malware analysis report

Static analysis result for SHA-256 f19b4b7c4fbcac88…

MALICIOUS

PDF

19.5 KB Created: 2019-05-01 17:22:15 +01:00 Authoring application: mPDF 5.7
MD5: 1e85b8a90c97b31e0d11aca78eb500cd SHA-1: c5b8a564d897ae4cbd9b0fee793332167ccec837 SHA-256: f19b4b7c4fbcac884cf5c8195440a190c8de2dddc67112eca0a71c135629225f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, many of which are hosted on the domain loaminoo.linkpc.net. This behavior is indicative of a link farm or a lure to download further malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091099096094093/Mystical-Emona-Soul-s-Journey-by-Ronesa-Aveela.pdf
    • http://loaminoo.linkpc.net/1092091091098094/A-Witch-s-Love-Story-A-mystical-journey-through-time-and-beyond-by-Vatsala-Sinha.pdf
    • http://loaminoo.linkpc.net/4090097091092090/The-Book-of-Mystical-Chapters-Meditations-on-the-Soul-s-Ascent-from-the-Desert-Fathers-and-Other-Early-Christian-Contemplatives-by-John-Anthony-McGuckin.pdf
    • http://loaminoo.linkpc.net/1090094099099090091/Body-and-Soul-The-Inner-Journey-by-Ilana-Weibel.pdf
    • http://loaminoo.linkpc.net/4092097098099/The-Untethered-Soul-The-Journey-Beyond-Yourself-by-Michael-A-Singer.pdf
    • http://loaminoo.linkpc.net/2092093090099090/How-To-Know-God-The-Soul-s-Journey-Into-The-Mystery-Of-Mysteries-by-Deepak-Chopra.pdf
    • http://loaminoo.linkpc.net/4098094094095092/The-Tech-War-Kiah-s-Soul-Shifting-Journey-2-by-Ann-Denton.pdf
    • http://loaminoo.linkpc.net/5091094099093/Take-a-Closer-Look-A-Spiritual-Journey-Into-the-Soul-by-Harel-R-Lawrence.pdf
    • http://loaminoo.linkpc.net/2092093092096094/God-Creation-and-Tools-for-Life-Journey-of-the-Soul-1-by-Sylvia-Browne.pdf
    • http://loaminoo.linkpc.net/2092093092093090/The-Nature-of-Good-and-Evil-Journey-of-the-Soul-3-by-Sylvia-Browne.pdf
    • http://loaminoo.linkpc.net/3092090098096096/Ageless-Soul-The-Lifelong-Journey-Toward-Meaning-and-Joy-by-Thomas-Moore.pdf
    • http://loaminoo.linkpc.net/3099098098097091/Compass-The-Journey-of-the-Soul-from-Egypt-to-the-Promised-Land-by-Penelope-V-Yorke.pdf
    • http://loaminoo.linkpc.net/4090096092097090/Soul-Process-Tools-for-Transformation-a-Journey-of-Love-by-Paul-E-McAtarsney.pdf
    • http://loaminoo.linkpc.net/3092091091090094/No-Way-Out-But-Through-One-Man-s-Journey-from-Mental-Illness-to-Clarity-and-Strength-of-Soul-by-Graham-Aitchison.pdf
    • http://loaminoo.linkpc.net/3092091097096094/Brave-Soul-A-Healer-s-Journey-into-Spiritual-Awakening-by-Amber-Nightingale.pdf
    • http://loaminoo.linkpc.net/9096091096097/Soul-Revival-A-40-Days-Journey-to-the-Feet-of-Christ-by-Ramos-Talaya.pdf
    • http://loaminoo.linkpc.net/3094092095097098/God-Save-Texas-A-Journey-Into-the-Soul-of-the-Lone-Star-State-by-Lawrence-Wright.pdf
    • http://loaminoo.linkpc.net/7098098095/God-Save-Texas-A-Journey-Into-the-Soul-of-the-Lone-Star-State-by-Lawrence-Wright.pdf
    • http://loaminoo.linkpc.net/1096096091093094/Reflections-of-a-Tortured-Soul-one-hearts-journey-through-the-pain-of-love-and-life-by-Eric-Mastel.pdf
    • http://loaminoo.linkpc.net/3094095094092091/Soul-Whispers-II-Secret-Alchemy-of-the-Elements-in-Soul-Coaching-Soul-Whispers-2-by-Denise-Linn.pdf
    • http://loaminoo.linkpc.net