Malicious PDF — malware analysis report

Static analysis result for SHA-256 54888a9b89a609c4…

MALICIOUS

PDF

13.3 KB Created: 2019-05-02 17:30:24 +01:00 Authoring application: mPDF 5.7
MD5: 952228486237f2bf0f3132b319f29e3f SHA-1: 0b870c92dcc879d97b823dc7c30a0143ce913872 SHA-256: 54888a9b89a609c4812a138e2c2700c6080be89391dcdbf81fb39569bbef737d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the 'loaminoo.linkpc.net' domain. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a link farm or a mechanism to distribute potentially malicious content or manipulate search engine results. The document body is heavily obfuscated, preventing a clear understanding of its direct intent beyond linking.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090094091093098/The-Girl-of-the-Wish-Garden-by-Uma-Krishnaswami.pdf
    • http://loaminoo.linkpc.net/1092093091095096/Ganesha-by-Kamala-Chandrakant.pdf
    • http://loaminoo.linkpc.net/9098093096090091/The-Coffer-Dams-by-Kamala-Markandaya.pdf
    • http://loaminoo.linkpc.net/3096093090096/Nectar-in-a-Sieve-by-Kamala-Markandaya.pdf
    • http://loaminoo.linkpc.net/1093098090094096/A-Handful-of-Rice-by-Kamala-Markandaya.pdf
    • http://loaminoo.linkpc.net/4099097098095094/The-God-in-the-Middle-by-Satyajit-Nair.pdf
    • http://loaminoo.linkpc.net/4094099094096095/Mistress-by-Anita-Nair.pdf
    • http://loaminoo.linkpc.net/6097093091094/Mistress-by-Anita-Nair.pdf
    • http://loaminoo.linkpc.net/7093095093094090/Tales-of-Maryada-Rama-by-Kamala-Chandrakant.pdf
    • http://loaminoo.linkpc.net/9097097094093/Ladies-Coup-by-Anita-Nair.pdf
    • http://loaminoo.linkpc.net/7093095093095093/Ancestors-of-Rama-A-Noble-Inheritance-by-Kamala-Chandrakant.pdf
    • http://loaminoo.linkpc.net/7093095092092093/Dasharatha-The-Story-of-Rama-s-Father-by-Kamala-Chandrakant.pdf
    • http://loaminoo.linkpc.net/2099093090098092/To-the-sacred-valley-with-Koko-by-Ayyappan-Nair.pdf
    • http://loaminoo.linkpc.net/1091092090095097099/Glimpses-of-Mordern-Prose-by-N-Ramachandran-Nair.pdf
    • http://loaminoo.linkpc.net/8094095099093093/Short-Sories-From-Life---Vol-I-by-Manoj-Nair.pdf
    • http://loaminoo.linkpc.net/8091090098092090/And-the-Mountains-Echoed-by-Khaled-Hosseini-by-Kajal-Nair.pdf
    • http://loaminoo.linkpc.net/2090093095091093/Potluck-Culture-Five-Strategies-to-Engage-the-Modern-Workplace-by-Ranjit-Nair.pdf
    • http://loaminoo.linkpc.net/9098097092091090/Piggies-on-the-Railway-A-Kasthuri-Kumar-Mystery-by-Smita-Nair-Jain.pdf
    • http://loaminoo.linkpc.net/4095095091099092/Humility-Garden-Garden-of-Salt-1-by-Felicity-Savage.pdf
    • http://loaminoo.linkpc.net/7091098099093098/The-Edible-Garden-How-to-Have-Your-Garden-and-Eat-It-Too-by-Alys-Fowler.pdf
    • http://loaminoo.linkpc.net/1091092090095097099/Glimpses-of-Morde