Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9e11ea99bc38829…

MALICIOUS

PDF

14.6 KB Created: 2019-05-04 14:11:36 +01:00 Authoring application: mPDF 5.7
MD5: a2faf45eb48f3f33aebea42bc37643f0 SHA-1: 1a0a4fea3a860087c0ae9abf808a8680a7d079e9 SHA-256: f9e11ea99bc3882998e4e40d33e618f58d962cc20798e0c4ae386e8dc210f72e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a significant number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. While most of these links point to benign book titles, the sheer volume and the dominant host 'loaminoo.linkpc.net' suggest a malicious intent, possibly for SEO poisoning or as a distribution point for further malware. The ML classifier also flagged this PDF with high confidence. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6097092093095095/The-Ties-That-Bind-Never-Forgotten-by-S-A-J-Friederich.pdf
    • http://loaminoo.linkpc.net/7092098093090092/The-Ties-That-Bind-by-Vanessa-Duri-s.pdf
    • http://loaminoo.linkpc.net/3094099096098094/Ties-That-Bind-by-Heather-Huffman.pdf
    • http://loaminoo.linkpc.net/3099095098095091/The-Ties-That-Bind-by-Erin-Kelly.pdf
    • http://loaminoo.linkpc.net/2097098097098099/The-Tangled-Ties-That-Bind-by-Mary-Connealy.pdf
    • http://loaminoo.linkpc.net/1095097093093095/The-Price-of-Faith-The-Ties-That-Bind-3-by-Rob-J-Hayes.pdf
    • http://loaminoo.linkpc.net/7090099097095097/The-Ties-That-Bind-An-as-I-Lay-Dying-Novel-by-Katie-Miller.pdf
    • http://loaminoo.linkpc.net/2093099098096092/The-Colour-of-Vengeance-The-Ties-That-Bind-2-by-Rob-J-Hayes.pdf
    • http://loaminoo.linkpc.net/3092098091099095/Ties-That-Bind-The-Bellum-Sisters-3-by-T-A-Grey.pdf
    • http://loaminoo.linkpc.net/7093090099098097/The-Ties-That-Bind-Ariel-Kimber-4-by-Mary-Martel.pdf
    • http://loaminoo.linkpc.net/1091093092095094/Holding-On-and-Letting-Go-The-Ties-That-Bind-Us-1-by-Lucy-A-Kelly.pdf
    • http://loaminoo.linkpc.net/6093093093093098/The-Ties-That-Bind-Bruce-Springsteen-A-to-Z-by-Gary-Graff.pdf
    • http://loaminoo.linkpc.net/2099095098095098/Bound-for-the-Holidays-Ties-That-Bind-1-by-Mackenzie-McKade.pdf
    • http://loaminoo.linkpc.net/3098098096090095/The-Ties-That-Bind-Slave-World-2-by-Johnny-Stone.pdf
    • http://loaminoo.linkpc.net/4097097099097090/Blood-Lines-Book-1-Ties-That-Bind-by-Mehran-Khan.pdf
    • http://loaminoo.linkpc.net/8093095098097096/Ties-that-bind-Communities-in-American-history-by-Lisa-B-Auel.pdf
    • http://loaminoo.linkpc.net/4099099094095096/Ties-that-Bind-The-Amish-of-Summer-Grove-1-by-Cindy-Woodsmall.pdf
    • http://loaminoo.linkpc.net/1096099098093097/Killing-Time-Ties-That-Bind-Trilogy-1-by-Elle-Chardou.pdf
    • http://loaminoo.linkpc.net/8095092098094090/1886-Ties-That-Bind-A-Story-of-Politics-Graft-and-Greed-by-A-E-Wasserman.pdf
    • http://loaminoo.linkpc.net/4098092098092098/Ties-That-Bind-Celestial-Wars-Saga-Book-1-by-Karen-Buckeridge.pdf
    • http://loaminoo.linkpc.net/2099095098095098/Bound-for-the-Holidays-Ties-That-Bind-1-by-Mackenzie-