Malicious PDF — malware analysis report

Static analysis result for SHA-256 55e50325d96aabd3…

MALICIOUS

PDF

16.3 KB Created: 2019-04-30 03:40:49 +01:00 Authoring application: mPDF 5.7
MD5: 54439274b8067eae1589f6c1bcee0712 SHA-1: 06d6e268fa9f7b2657526f2553bb8befbff30ba7 SHA-256: 55e50325d96aabd3c975118677f67de10753f140d593a983ddda9736514390d5
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents, all hosted on the domain 'loaminoo.linkpc.net'. This pattern is indicative of a link farm or a phishing lure designed to direct users to potentially malicious content. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.n
    • http://loaminoo.linkpc.net/1092095094094099/Witch-The-Spell-Within-The-Witch-Series-Book-2-by-L-S-Gagnon.pdf
    • http://loaminoo.linkpc.net/4097096095098097/Return-Of-The-Witch-Detective-Marcella-Witch-s-series-9-by-Dana-E-Donovan.pdf
    • http://loaminoo.linkpc.net/1098092092091098/Witch-Devotions-The-Last-Witch-Series-3-by-Elizabeth-J-Kolodziej.pdf
    • http://loaminoo.linkpc.net/4091097095097095/Water-Witch-Blood-Witch-Bone-Witch-Witches-of-Etlantium-1-3-by-Thea-Atkinson.pdf
    • http://loaminoo.linkpc.net/1096097091098091/The-Inheritance-of-a-Swamp-Witch-The-Swamp-Witch-Series-by-Sonia-Taylor-Brock.pdf
    • http://loaminoo.linkpc.net/3097094099092092/The-Worst-Witch-Saves-The-Day-Worst-Witch-Book-5-by-Jill-Murphy.pdf
    • http://loaminoo.linkpc.net/1091090090099099093/Witch-Children-From-Salem-Witch-Hunts-to-Modern-Courtrooms-by-Hans-Sebald.pdf
    • http://loaminoo.linkpc.net/1091099094099099/The-Briley-Witch-Chronicles-Books-1-and-2-The-Spirit-of-a-Witch-Storm-Grey-by-Sarah-Jane-Avory.pdf
    • http://loaminoo.linkpc.net/3097096098094092/Witch-Is-Why-The-Music-Stopped-A-Witch-P-I-Mystery-19-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098096095/Witch-Is-When-Life-Got-Complicated-A-Witch-P-I-Mystery-2-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098094093/Witch-Is-Why-The-Wolf-Howled-A-Witch-P-I-Mystery-18-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/1096099092095095/Sex-and-the-Psychic-Witch-Triplet-Witch-Trilogy-1-by-Annette-Blair.pdf
    • http://loaminoo.linkpc.net/2090096099096/My-Favorite-Witch-Accidental-Witch-Trilogy-2-by-Annette-Blair.pdf
    • http://loaminoo.linkpc.net/3097096098096092/Witch-is-When-The-Bubble-Burst-A-Witch-P-I-Mystery-5-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098095091/We-Witch-You-A-Merry-Christmas-A-Witch-P-I-Mystery-5-5-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098095098/Witch-Is-When-The-Hammer-Fell-A-Witch-P-I-Mystery-8-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098096091/Witch-is-When-The-Penny-Dropped-A-Witch-P-I-Mystery-6-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098096093/Witch-Is-When-Things-Fell-Apart-A-Witch-P-I-Mystery-4-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/2097096097099092/A-Reckless-Witch-A-Modern-Witch-3-by-Debora-Geary.pdf
    • http://loaminoo.linkpc.net/6092097093094094/Fried-Green-Witch-Bless-Your-Witch-8-by-Amy-Boyles.pdf