Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7fe98cc84d038b1…

MALICIOUS

PDF

17.2 KB Created: 2019-05-02 02:30:40 +01:00 Authoring application: mPDF 5.7
MD5: 1335cffc59fc443f46b44d6410a9e505 SHA-1: 12fe2c6ba3bd3e4d544091ae4d2010e83d909643 SHA-256: f7fe98cc84d038b11cfde12e202458672377cfefc7ab313c057caac651908cc5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the 'loaminoo.linkpc.net' domain. This heuristic firing indicates a link farm, likely intended to drive traffic or potentially serve as a distribution point for further malicious content. No scripts were extracted from this sample, and the document body was unreadable. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.ne
    • http://loaminoo.linkpc.net/5093093098094092/Der-Lustmolch-Roman-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/3096097090095099/A-Dirty-Job-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/3090096093090/Sacr-Bleu-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/3095093095097099/Coyote-Blue-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/8095096094095/Coyote-Blue-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/9090093094090091/Sacre-Bleu-A-Comedy-d-Art-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/3095097091096095/Secondhand-Souls-Grim-Reaper-2-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/2091092096099098/Bloodsucking-Fiends-A-Love-Story-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/3099091099094095/The-Stupidest-Angel-Pine-Cove-3-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/2090099091098093/Fluke-Or-I-Know-Why-the-Winged-Whale-Sings-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/1091090095095097093/The-Stupidest-Angel-with-Bonus-Material-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/7094092097094091/Dog-Food-for-the-Soul-San-Diego-amp-Nouveau-Roman-Stories-by-Kealan-Moore.pdf
    • http://loaminoo.linkpc.net/3098094092091098/Santa-and-Pete-A-Novel-of-Christmas-Present-and-Past-by-Christopher-Paul-Moore.pdf
    • http://loaminoo.linkpc.net/3090091095093091/The-Stupidest-Angel-v2-0-A-Heartwarming-Tale-of-Christmas-Terror-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/5095093098099093/Coinage-and-Identity-in-the-Roman-Provinces-by-Christopher-Howgego.pdf
    • http://loaminoo.linkpc.net/1090091099092097092/Dishonored-Zersplittert-Roman-zum-Videogame-by-Adam-Christopher.pdf
    • http://loaminoo.linkpc.net/1094093090091098/The-Stupidest-Angel-A-Heartwarming-Tale-of-Christmas-Terror-Pine-Cove-3-by-Christopher-Moore.pdf
    • http://loaminoo.linkpc.net/6093096094096098/Render-to-Caesar-Jesus-the-Early-Church-and-the-Roman-Superpower-by-Christopher-Bryan.pdf
    • http://loaminoo.linkpc.net/2099097099091092/A-Most-Dangerous-Book-Tacitus-s-Germania-from-the-Roman-Empire-to-the-Third-Reich-by-Christopher-B-Krebs.pdf
    • http://loaminoo.linkpc.net/4090093093098096/Chronicle-of-the-Roman-Emperors-The-Reign-by-Reign-Record-of-the-Rulers-of-Imperial-Rome-by-Christopher-Scarre.pdf