Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5c52e5cde2b020f…

MALICIOUS

PDF

17.4 KB Created: 2019-04-29 22:59:54 +01:00 Authoring application: mPDF 5.7 First seen: 2021-07-13
MD5: 22e16c82a919392d5a5afd3a7effb065 SHA-1: 989e96917162ab4d88385f715d1afcd279190a7a SHA-256: e5c52e5cde2b020fc39bb3261c7eefe215a4f5a96c8eb7e505dd03189f0816cd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on the 'loaminoo.linkpc.net' domain, suggesting a potential SEO poisoning or link farm tactic to direct users to malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6099099092092/Junie-B-Jones-is-a-Graduation-Girl-amp-Junie-B-First-Grader-at-Last-Junie-B-Jones-17-18-by-Barbara-Park.pdf In PDF document text
    • http://loaminoo.linkpc.net/7094098091092/Junie-B-First-Grader-Cheater-Pants-Junie-B-Jones-21-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7092091090093/Junie-B-First-Grader-Jingle-Bells-Batman-Smells-P-S-So-Does-May-Junie-B-Jones-25-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/8090094093097/Junie-B-First-Grader-Shipwrecked-Junie-B-Jones-23-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3091093094098092/Junie-B-First-Grader-Aloha-ha-ha-Junie-B-Jones-26-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3091094097092099/Junie-B-First-Grader-Aloha-ha-ha-Junie-B-Jones-26-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7093090095096/Junie-B-First-Grader-at-Last-Junie-B-Jones-18-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1098090097098094/Junie-B-Jones-Loves-Handsome-Warren-Junie-B-Jones-7-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3091093095092099/Junie-B-Jones-and-That-Meanie-Jim-s-Birthday-Junie-B-Jones-6-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3091093096093097/Junie-B-Jones-Is-a-Party-Animal-Junie-B-Jones-10-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4097090094091099/Junie-B-Jones-and-a-Little-Monkey-Business-Junie-B-Jones-2-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3091094097090092/Junie-B-Jones-28-Turkeys-We-Have-Loved-and-Eaten-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3091096094093090/Turkeys-We-Have-Loved-and-Eaten-and-Other-Thankful-Stuff-Junie-B-Jones-28-by-Barbara-Park.pdfIn PDF document text
    • http://loaminoo.linkpc.net/4093096091096098/Junie-Moon-Rising-by-June-Collins.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1091096091094094095/Archaeological-Research-In-Kakadu-National-Park-by-Rhys-Jones.pdfIn PDF document text
    • http://loaminoo.linkpc.net/7098095094093090/The-Lost-Journal-of-Indiana-Jones-by-Henry-Jones-Jr-.pdfIn PDF document text
    • http://loaminoo.linkpc.net/1094091098092094/Autobiography-of-Mother-Jones-by-Mary-Harris-Jones.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3095097096098093/Girl-Hero-by-Carrie-Jones.pdfIn PDF document text
    • http://loaminoo.linkpc.net/2096091092096097/The-Last-Final-Girl-by-Stephen-Graham-Jones.pdfIn PDF document text
    • http://loaminoo.linkpc.net/3097098096090098/Love-and-an-American-Girl-by-Violet-Jones.pdfIn PDF document text