Malicious PDF — malware analysis report

Static analysis result for SHA-256 2891e8e23b91f21d…

MALICIOUS

PDF

14.8 KB Created: 2019-04-30 05:54:57 +01:00 Authoring application: mPDF 5.7
MD5: d053c3dc634b84aa5e5ea73a3f38186b SHA-1: ddb4e5ed2d35df07ce1eb12e8011b14ee83c2106 SHA-256: 2891e8e23b91f21dd17b522ec7680ec0b3d0efcf125cb8dd36d3954d840ff16f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

This PDF file contains a large number of embedded URLs pointing to other PDF documents on the 'loaminoo.linkpc.net' domain. The heuristic 'PDF_SEO_LINK_FARM' indicates this is a link farm, suggesting a tactic to manipulate search engine results or redirect traffic. While the document body is heavily obfuscated, the presence of numerous links to external PDFs strongly suggests a malicious intent related to SEO poisoning or traffic diversion.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9798

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2091091096097090/Discovering-April-Discovering-Trilogy-1-by-Sheena-Hutchinson.pdf
    • http://loaminoo.linkpc.net/3090091091096096/Discovering-Ren-Discovering-Ren-1-by-Jennifer-Eifrig.pdf
    • http://loaminoo.linkpc.net/1092095090097099/The-Awakening-Seraphina-1-by-Sheena-Hutchinson.pdf
    • http://loaminoo.linkpc.net/4090093095098091/Discovering-Aberration-by-S-C-Barrus.pdf
    • http://loaminoo.linkpc.net/6095099091096092/Discovering-QLO-by-Gina-Ardente.pdf
    • http://loaminoo.linkpc.net/7095099095093092/Seraphina-s-Initiation-Seraphina-2-by-Sheena-Hutchinson.pdf
    • http://loaminoo.linkpc.net/9099098091098/Supersoul-13-Discovering-the-Soul-of-God-by-Buddha-Z-.pdf
    • http://loaminoo.linkpc.net/4093090097096099/Discovering-Arugula-by-Elizabeth-Allen.pdf
    • http://loaminoo.linkpc.net/2095096093098092/Unearthing-Cole-Discovering-Me-1-by-A-M-Arthur.pdf
    • http://loaminoo.linkpc.net/4098096092094099/Everything-as-it-should-be---discovering-Switzerland-by-Susan-Meredith.pdf
    • http://loaminoo.linkpc.net/4095090099096098/Discovering-the-Character-of-God-by-George-MacDonald.pdf
    • http://loaminoo.linkpc.net/2096092099097099/Joy-on-Demand-The-Art-of-Discovering-the-Happiness-Within-by-Chade-Meng-Tan.pdf
    • http://loaminoo.linkpc.net/2093092096094095/Discovering-Africa-s-Past-by-Basil-Davidson.pdf
    • http://loaminoo.linkpc.net/2093095091096092/Discovering-God-s-Will-for-Your-Life-Your-Journey-with-God-by-Mike-Lutz.pdf
    • http://loaminoo.linkpc.net/2099096096091090/Discovering-Your-Amazing-Marriage-by-Jason-Coleman.pdf
    • http://loaminoo.linkpc.net/1090099092093091099/Discovering-the-Expanding-Universe-by-Harry-Nussbaumer.pdf
    • http://loaminoo.linkpc.net/9090095093090095/Discovering-The-Book-Of-Common-Prayer-by-Sue-Careless.pdf
    • http://loaminoo.linkpc.net/1091090094096090090/Journeying-to-the-One-Discovering-the-Beautiful-Names-of-God-by-Ali-Mermer.pdf
    • http://loaminoo.linkpc.net/5090099090095095/Discovering-Monaro-A-Study-of-Man-s-Impact-on-His-Environment-by-W-K-Hancock.pdf
    • http://loaminoo.linkpc.net/1091093091099092095/Discovering-Patterns-in-Mathematics-and-Poetry-by-Marcia-Birken.pdf
    • http://loaminoo.linkpc.net/2096092099097099/Joy-on-Demand-The-Art-of-Disco