Malicious PDF — malware analysis report

Static analysis result for SHA-256 26579f5cc838405c…

MALICIOUS

PDF

16.5 KB Created: 2019-05-02 17:51:54 +01:00 Authoring application: mPDF 5.7
MD5: ad5f63fc4a4aaac4225535c73ca4e071 SHA-1: e4d2d05cfd0ff0250421529e730bb85f03e8c576 SHA-256: 26579f5cc838405c28b6ffac7847991d73b30ccedd1fbe35dd280bcd7560b090
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded links, forming a link farm. The primary heuristic indicates this is a PDF SEO link farm, with most links pointing to numeric slugs on the 'loaminoo.linkpc.net' domain. While the URLs themselves are classified as benign, the sheer volume and structure suggest a malicious intent to distribute content or drive traffic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3095093097095099/Forget-Him-Not-The-Hellfire-Vampires-Bloodline-Book-3-by-Jae-T-Jaggart.pdf
    • http://loaminoo.linkpc.net/3095093097095098/His-Sweet-Prince-The-Hellfire-Vampires-Bloodline-2-by-Jae-T-Jaggart.pdf
    • http://loaminoo.linkpc.net/2093092092095090/Bloodline-Lands-of-Ayrenia-Chronicles-The-Bloodline-Saga-1-by-Katie-Thornton-K-.pdf
    • http://loaminoo.linkpc.net/1090097098098097/The-Hunters-Bloodline-Series-Book-1-by-Maria-Bunda.pdf
    • http://loaminoo.linkpc.net/3099095094096093/Forget-Me-Not-Love-in-the-Fleet-Book-2-by-Heather-Ashby.pdf
    • http://loaminoo.linkpc.net/3091090098090090/Forget-Me-Not-Phased-Moonlight-Series-Book-2-by-Kasey-Thompson.pdf
    • http://loaminoo.linkpc.net/4091093098098099/Objects-Of-His-Obsession-by-Jae-T-Jaggart.pdf
    • http://loaminoo.linkpc.net/7098092091091/The-Book-of-Blood-From-Legends-and-Leeches-to-Vampires-and-Veins-by-H-P-Newquist.pdf
    • http://loaminoo.linkpc.net/9096092093099099/ARINA-S-MATE-ARINA-S-MATE-Shifters-of-the-Bulgarian-Bloodline-Book-2-by-Dalia-Wright.pdf
    • http://loaminoo.linkpc.net/2094091093098093/Hellfire-by-Ed-Macy.pdf
    • http://loaminoo.linkpc.net/4090095097096092/The-Hellfire-Legacy-by-Missouri-Dalton.pdf
    • http://loaminoo.linkpc.net/6096091094094097/trada-hellfire-by-atiq-rehman.pdf
    • http://loaminoo.linkpc.net/3090095091099094/HellFire-DemonSlayers-2-by-Kate-Douglas.pdf
    • http://loaminoo.linkpc.net/2097099095096093/The-Hellfire-Club-by-Jake-Tapper.pdf
    • http://loaminoo.linkpc.net/2091092094094094/The-Hellfire-Club-by-Peter-Straub.pdf
    • http://loaminoo.linkpc.net/7098096098/The-Hellfire-Club-by-Jake-Tapper.pdf
    • http://loaminoo.linkpc.net/4096092097094091/The-Everything-Vampire-Book-From-Vlad-the-Impaler-to-the-vampire-Lestat---a-history-of-vampires-in-Literature-Film-and-Legend-by-Barbara-Karg.pdf
    • http://loaminoo.linkpc.net/3092096090095090/Hellfire-and-Kittens-Queen-Lucy-1-by-Rhiannon-Lee.pdf
    • http://loaminoo.linkpc.net/3098091091097091/Real-Vampires-Do-It-in-the-Dark-Real-Vampires-Don-t-Sparkle-2-by-Amy-Fecteau.pdf
    • http://loaminoo.linkpc.net/3099096093098/The-Morganville-Vampires-Volume-3-The-Morganville-Vampires-5-6-by-Rachel-Caine.pdf
    • http://loaminoo.linkpc.net/9096092093099099/ARINA-S-MATE-ARINA-S-MATE-Shifters-of-the-Bulgarian-Bloodline-Book-2-by-Dalia-W