Malicious PDF — malware analysis report

Static analysis result for SHA-256 db794588dd817658…

MALICIOUS

PDF

16.5 KB Created: 2019-04-29 23:07:59 +01:00 Authoring application: mPDF 5.7
MD5: 4db1036ae1df1d60d496c6c3cc32a2e0 SHA-1: 02a1aea9de3dc110f12ac9c2af07e59628fb1a78 SHA-256: db794588dd8176583c61d3c1368d27af4c342ea6786c75a57a782cdca5f85cbf
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links predominantly point to book titles hosted on the 'loaminoo.linkpc.net' domain. While the document body is heavily obfuscated and unreadable, the heuristic suggests a link farm tactic, likely for SEO manipulation or to host malicious content. The presence of numerous external links, even if currently labeled benign, points to a deceptive or manipulative attack pattern.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096095094092099/How-to-be-Good-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/2096096090098097/How-to-Be-Good-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/2097093092094099/How-To-Be-Good-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/4090093098094/Slam-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1090091093098092094/A-Long-Way-Down-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1090091096093096093/A-Long-Way-Down-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/4091093091091092/Not-A-Star-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/4096098094090096/Fever-Pitch-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/7091096097094093/Everyone-s-Reading-Bastard-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/8091099094094096/Alta-fidelidade-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/3092095096096099/Not-a-Star-and-Otherwise-Pandemonium-Stories-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/3091094090096093/Not-a-Star-and-Otherwise-Pandemonium-Stories-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1091090099096090093/Weniger-reden-und-fter-mal-in-die-Badewanne---Mein-Leben-als-Leser-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/2097091094099099/Books-Movies-Rhythm-Blues-Twenty-Years-of-Writing-About-Film-Music-and-Books-by-Nick-Hornby.pdf
    • http://loaminoo.linkpc.net/1093098093093097/Dino-Living-High-in-the-Dirty-Business-of-Dreams-by-Nick-Tosches.pdf
    • http://loaminoo.linkpc.net/9097094098098095/Nick-and-Tecla-s-High-Voltage-Danger-Lab-A-Mystery-with-Electromagnets-Burglar-Alarms-and-Other-Gadgets-You-Can-Build-Yourself-by-Pflugfelder.pdf
    • http://loaminoo.linkpc.net/8096092098094/Fidelity-Stories-by-Michael-Redhill.pdf
    • http://loaminoo.linkpc.net/1090094095097091090/Achieving-Higher-Fidelity-Conjunction-Analyses-Using-Cryptography-to-Improve-Information-Sharing-by-Brett-Hemenway.pdf
    • http://loaminoo.linkpc.net/1091096099098092097/Oxford-Advanced-Learner-s-Dictionary-by-A-S-Hornby.pdf
    • http://loaminoo.linkpc.net/7095097091094099/Toronto-and-the-Maple-Leafs-A-City-and-Its-Team-by-Lance-Hornby.pdf