Malicious PDF — malware analysis report

Static analysis result for SHA-256 249255d99f5e39ce…

MALICIOUS

PDF

13.5 KB Created: 2019-04-30 04:10:50 +01:00 Authoring application: mPDF 5.7
MD5: 18ed300f3d52c1e7fdf077c29c7d02bd SHA-1: f5016c077a68d7550c0de55bd844fad32906ac5c SHA-256: 249255d99f5e39ce17d9150cdeecf0ac27ecb2fe08fd7ed008140db9a07caca0
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier and contains a large number of embedded links, identified as a PDF_SEO_LINK_FARM heuristic. These links predominantly point to the 'loaminoo.linkpc.net' domain, suggesting a coordinated effort to distribute content or drive traffic. While the specific intent beyond link farming is unclear due to the lack of executable scripts or user-facing text, the sheer volume of links indicates a malicious distribution pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9877

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.l
    • http://loaminoo.linkpc.net/1097096095097095/Clive-Barker-s-Hellraiser-Vol-1-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/4098094093095097/Clive-Barker-s-Hellraiser-Collected-Best-I-by-D-G-Chichester.pdf
    • http://loaminoo.linkpc.net/7092094090093094/The-Essential-Clive-Barker-Selected-Fiction-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/7092094090092092/Incarnations-Three-Plays-by-Clive-Barker-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/2096093095092/Cabal-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/3095098096095092/Sacrament-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/2095090095098092/Sacrament-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/5098095096092/Imajica-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/3092099099091/Imajica-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/6097092099098091/Infernal-Parade-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/6093098097090095/Lord-of-Illusions-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/2095098092097093/The-Hellbound-Heart-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/2096093099099/The-Damnation-Game-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/2091092092091098/Absolute-Midnight-Abarat-3-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/3097095094093/Days-of-Magic-Nights-of-War-Abarat-2-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/2091095098094090/The-Inhuman-Condition-Books-of-Blood-4-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/7093092096090/The-Complete-Clive-Barker-s-The-Great-And-Secret-Show-by-Chris-Ryall.pdf
    • http://loaminoo.linkpc.net/7092094090092090/Clive-Barker-s-The-Great-And-Secret-Show-Volume-2-by-Chris-Ryall.pdf
    • http://loaminoo.linkpc.net/3093097096094098/Abarat-Days-of-Magic-Nights-of-War-Abarat-2-by-Clive-Barker.pdf
    • http://loaminoo.linkpc.net/2095099093096/Books-of-Blood-Volume-One-Books-of-Blood-1-by-Clive-Barker.pdf