Malicious PDF — malware analysis report

Static analysis result for SHA-256 49b00bc5dc0acf87…

MALICIOUS

PDF

16.4 KB Created: 2019-05-02 19:14:17 +01:00 Authoring application: mPDF 5.7
MD5: 2a66a0a0fca74bd90975115ef8ba920c SHA-1: 1468ea00aedbf16d5b6e1f63e762ac75dd5a318d SHA-256: 49b00bc5dc0acf87e2223655fca869d0493289787e1c31f4b7e38ba8127338ce
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by a machine learning classifier as malicious. Static analysis revealed a large number of embedded URLs, many of which are structured as book titles, suggesting a potential SEO manipulation or link farm tactic. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with a significant number of external links, pointing to the domain 'loaminoo.linkpc.net'. While the URLs themselves are currently marked as benign, the sheer volume and structure strongly suggest a malicious intent, likely to redirect users to harmful content or exploit SEO vulnerabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9898

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7092091097099092/Kirchberger-Et-L-Illuminisme-Du-Dix-Huitieme-Siecle-by-Antoine-Faivre.pdf
    • http://loaminoo.linkpc.net/8091093092092092/Theosophy-Imagination-Tradition-Studies-in-Western-Esotericism-by-Antoine-Faivre.pdf
    • http://loaminoo.linkpc.net/8094090091096/The-Golden-Fleece-by-Robert-Graves.pdf
    • http://loaminoo.linkpc.net/1090098091096095099/Argonautica-Jason-and-the-Golden-Fleece-Translated-by-Edward-P-Coleridge-Illustrated-by-A-Tassos-by-Moses-Ha.pdf
    • http://loaminoo.linkpc.net/5091093093095096/Spain-s-Golden-Fleece-Wool-Production-and-the-Wool-Trade-from-the-Middle-Ages-to-the-Nineteenth-Century-by-Carla-Rahn-Phillips.pdf
    • http://loaminoo.linkpc.net/2099096091099099/Real-Alchemy-A-Primer-of-Practical-Alchemy-by-Robert-Allen-Bartlett.pdf
    • http://loaminoo.linkpc.net/8091093093099091/How-to-Raise-Rabbits-for-Fun-amp-Profit-by-Milton-I-Faivre.pdf
    • http://loaminoo.linkpc.net/8091093092093093/The-Emergence-of-the-Laity-in-the-Early-Church-by-Alexandre-Faivre.pdf
    • http://loaminoo.linkpc.net/7091096093096096/Antoine-de-Saint-Exup-ry-Le-Petit-Prince-by-Antoine-de-Saint-Exup-ry.pdf
    • http://loaminoo.linkpc.net/2098091096090097/Dreams-of-the-Golden-Age-Golden-Age-2-by-Carrie-Vaughn.pdf
    • http://loaminoo.linkpc.net/1094091095091098/The-Golden-Transcendence-Golden-Age-3-by-John-C-Wright.pdf
    • http://loaminoo.linkpc.net/1093090091090098/Alchemy-by-Ailsa-Abraham.pdf
    • http://loaminoo.linkpc.net/3095092093093096/Alchemy-by-Marie-S-Crosswell.pdf
    • http://loaminoo.linkpc.net/1099095091092099/Golden-Golden-1-by-Melinda-Michaels.pdf
    • http://loaminoo.linkpc.net/7094091094097093/The-Complete-Golden-Dawn-Cipher-Manuscript-Golden-Dawn-Studies-No-1-by-Darcy-Kuntz.pdf
    • http://loaminoo.linkpc.net/3090091093094097/The-Alchemy-of-Stone-by-Ekaterina-Sedia.pdf
    • http://loaminoo.linkpc.net/1094091093090093/Kabuki-Vol-7-The-Alchemy-by-David-W-Mack.pdf
    • http://loaminoo.linkpc.net/2093093093/The-Rising-The-Alchemy-Wars-2-by-Ian-Tregillis.pdf
    • http://loaminoo.linkpc.net/3096093099094097/The-Alchemy-of-Desire-by-Crista-McHugh.pdf
    • http://loaminoo.linkpc.net/8093094091099098/Arson-and-Alchemy-by-Harli-Palme.pdf