Malicious PDF — malware analysis report

Static analysis result for SHA-256 4883492ed1601c34…

MALICIOUS

PDF

20.6 KB Created: 2019-05-01 19:43:48 +01:00 Authoring application: mPDF 5.7
MD5: 949f5a3e293f28e01685a510ec6b9b64 SHA-1: 32c3d9e59b5cdb147da66cbb07100c1650e485a9 SHA-256: 4883492ed1601c347b62e871f28b1f5d14f844e068e24a20755318d735e214af
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains a link farm with 32 external links, primarily pointing to loaminoo.linkpc.net. This heuristic suggests the document is designed to drive traffic to a large number of websites, likely for SEO manipulation or to host malicious content. No scripts were extracted from this sample, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092098097095093/Child-of-Satan-Child-of-God-by-Susan-Atkins---Whitehouse.pdf
    • http://loaminoo.linkpc.net/1096091098090091/Child-of-Satan-Child-of-God-by-Bob-Slosser.pdf
    • http://loaminoo.linkpc.net/3095098092093098/The-Other-Child-by-Lucy-Atkins.pdf
    • http://loaminoo.linkpc.net/4093095098093091/Global-Child-Welfare-and-Well-Being-Global-Child-Welfare-and-Well-Being-by-Susan-C-Mapp.pdf
    • http://loaminoo.linkpc.net/3099099098097091/Roots-of-Empathy-Changing-the-World-Child-by-Child-by-Mary-Gordon.pdf
    • http://loaminoo.linkpc.net/3095096099099095/When-your-Child-is-6-to-12-Middle-Childhood-Is-The-Last-Good-Chance-To-Hold-Your-Child-Close-by-John-M-Drescher.pdf
    • http://loaminoo.linkpc.net/9097091091093093/The-Child-and-the-State-in-India-Child-Labor-and-Education-Policy-in-Comparative-Perspective-by-Myron-Weiner.pdf
    • http://loaminoo.linkpc.net/1091091092092090099/Grieving-the-Child-I-Never-Knew-A-Devotional-for-Comfort-in-the-Loss-of-Your-Unborn-or-Newly-Born-Child-by-Kathe-Wunnenberg.pdf
    • http://loaminoo.linkpc.net/1090091097092091/To-a-Child-Love-Is-Spelled-Time-What-a-Child-Really-Needs-from-You-by-Mac-Anderson.pdf
    • http://loaminoo.linkpc.net/1090093094092094/Child-of-Faerie-Child-of-Earth-by-Jane-Yolen.pdf
    • http://loaminoo.linkpc.net/7094096095093/No-Child-of-Mine-by-Susan-Lewis.pdf
    • http://loaminoo.linkpc.net/3093096098093093/No-Child-of-Mine-by-Susan-Lewis.pdf
    • http://loaminoo.linkpc.net/1090096093093098090/Biker-Chicks-Volume-3-by-Susan-Child.pdf
    • http://loaminoo.linkpc.net/4095098094097096/Child-Care-A-Comprehensive-Guide-4-Volumes-Volume-1--Rationale-for-Child-Care-Services-Programs-Vs-Politics-by-Stevanne-Auerbach.pdf
    • http://loaminoo.linkpc.net/3099099095097097/Between-Parent-and-Child-The-Bestselling-Classic-That-Revolutionized-Parent-Child-Communication-by-Haim-G-Ginott.pdf
    • http://loaminoo.linkpc.net/2098095098092090/Phoenix-Child-Phoenix-Child-1-by-Alica-McKenna-Johnson.pdf
    • http://loaminoo.linkpc.net/5092091095093/Child-Witch-Kinshasa-Child-Witch-1-by-Mike-Ormsby.pdf
    • http://loaminoo.linkpc.net/1090094091098091096/Child-Adolescent-Mental-Health-CNS-Review-Child-Adolescent-Nurse-Review-Book-1-by-Kathleen-Courtney.pdf
    • http://loaminoo.linkpc.net/2091095091090093/Marie-Th-r-se-Child-of-Terror-The-Fate-of-Marie-Antoinette-s-Daughter-by-Susan-Nagel.pdf
    • http://loaminoo.linkpc.net/4092095098096095/Marie-Th-r-se-Child-of-Terror-The-Fate-of-Marie-Antoinette-s-Daughter-by-Susan-Nagel.pdf
    • http://loaminoo.linkpc.net/1091091092092090099