Malicious PDF — malware analysis report

Static analysis result for SHA-256 1af04ccf6c083d01…

MALICIOUS

PDF

18.9 KB Created: 2019-05-06 16:32:44 +01:00 Authoring application: mPDF 5.7
MD5: 44fcf488865ceb1745b4f1bf4e48a06e SHA-1: 92bd88734be13524f7b5a256a8785f10efab201c SHA-256: 1af04ccf6c083d01fc69e31a0ae1ef17fa7a37c7c1fb2e9caa7876b61a4b4047
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file was identified as malicious due to a critical heuristic firing for a PDF SEO link farm. It contains numerous embedded links, primarily pointing to book titles hosted on loaminoo.linkpc.net. While the document body is heavily corrupted and unreadable, the presence of a large number of external links suggests an attempt to manipulate search engine results or distribute content through a link farm. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2090097096094097/Thorn-Bears-of-Burden-1-by-Candace-Ayers.pdf
    • http://loaminoo.linkpc.net/8096093090096096/Mating-the-Panther-by-Candace-Ayers.pdf
    • http://loaminoo.linkpc.net/1091094099092095096/Military-Bear-s-Mate-Kodiak-Island-Shifters-3-by-Candace-Ayers.pdf
    • http://loaminoo.linkpc.net/4091097094097096/Prince-of-Luster-Crimson-Romance-Series-3-by-Candace-Sams.pdf
    • http://loaminoo.linkpc.net/3099096095091096/The-Lady-Chapel-The-Owen-Archer-Series---Book-Two-by-Candace-Robb.pdf
    • http://loaminoo.linkpc.net/6095097092094094/Pacific-Northwest-Bears-The-Rochon-Brothers-Series-by-Moxie-North.pdf
    • http://loaminoo.linkpc.net/9090090098099095/The-Volkov-Brothers-Series-The-Complete-Series-by-Leslie-North.pdf
    • http://loaminoo.linkpc.net/9098093098096093/Chicago-Bears-Where-Have-You-Gone-Dick-Butkus-Gale-Sayers-Mike-Ditka-and-Other-Bears-Greats-by-Lew-Freedman.pdf
    • http://loaminoo.linkpc.net/1097098098092095/Iron-amp-Wine-The-Iron-World-Series-1-by-Candace-Osmond.pdf
    • http://loaminoo.linkpc.net/3096091090090091/Zombie-D-O-A-Series-Three-The-Complete-Series-Three-by-J-J-Zep.pdf
    • http://loaminoo.linkpc.net/9090099091092/The-Complete-Little-Women-Series-Little-Women-Good-Wives-Little-Men-Jo-s-Boys-The-Beloved-Classics-of-American-Literature-The-coming-of-age-series-experiences-with-her-three-sisters-by-Louisa-May-Alcott.pdf
    • http://loaminoo.linkpc.net/3095094090092096/Complete-Harlow-Series-Beneath-Him-Embracing-Him-Completing-Him-Harlow-Series-1-3-by-C-Shell.pdf
    • http://loaminoo.linkpc.net/3091090095091094/The-Complete-Now-Series-Now-1-3-by-Brenda-Rothert.pdf
    • http://loaminoo.linkpc.net/4094093090092099/Here-and-Now-Complete-Series-Here-and-Now-1-3-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/3091091090091094/FIGHT-The-Complete-Series-by-M-Dauphin.pdf
    • http://loaminoo.linkpc.net/2091096096099091/The-Complete-Secrets-Series-by-L-K-Shaw.pdf
    • http://loaminoo.linkpc.net/2092096099093098/Here-and-Now-Complete-Series-Here-and-Now-1-3-by-Lexi-Ryan.pdf
    • http://loaminoo.linkpc.net/4092095093090093/A-Desperate-Man-The-Complete-Series-by-Ella-Frank.pdf
    • http://loaminoo.linkpc.net/1094098091091096/Uninhibited-The-Complete-Series-by-Kimberly-Bracco.pdf
    • http://loaminoo.linkpc.net/4094098094096098/Nunslinger-The-Complete-Series-by-Stark-Holborn.pdf