Malicious PDF — malware analysis report

Static analysis result for SHA-256 27354e7df709203a…

MALICIOUS

PDF

15.2 KB Created: 2019-04-30 04:32:23 +01:00 Authoring application: mPDF 5.7
MD5: 5d1ac9988d5686a902059dc8025a1117 SHA-1: e359cbcbc26cdbf60528b04137b0ff8edf18d2fc SHA-256: 27354e7df709203a37b158dc509bcd8742645ccf3f60a644df46b612550db1bf
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, constituting a link farm. The primary heuristic identified this as a PDF_SEO_LINK_FARM, indicating a likely attempt to drive traffic to external sites. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to distribute content or potentially lead users to malicious sites through indirect means. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2094095094099090/Sissy-Side-Effects-by-Crystal-Summers.pdf
    • http://loaminoo.linkpc.net/2094095095096090/Sissy-s-Surprise-by-Crystal-Veeyant.pdf
    • http://loaminoo.linkpc.net/2094095094099093/Hypnotized-Boss-by-Crystal-Summers.pdf
    • http://loaminoo.linkpc.net/2094095094098093/Gender-Potion-Mix-Up-by-Crystal-Summers.pdf
    • http://loaminoo.linkpc.net/2099095098099094/Embrace-the-Night-Night-1-by-Crystal-Jordan.pdf
    • http://loaminoo.linkpc.net/1091097090093096096/Using-The-Sissy-Next-Door-Christina-s-feminization-part-2-Sissy-Christina-Book-3-by-Melinda-Streng.pdf
    • http://loaminoo.linkpc.net/1097096094099098/Don-t-Bite-the-Messenger-NIght-Runner-0-5-by-Regan-Summers.pdf
    • http://loaminoo.linkpc.net/6093090097094098/Sanctuary-at-Pepin-View-Manor-Pepin-Manor-Mystery-by-Jo-Williams.pdf
    • http://loaminoo.linkpc.net/6093092098093097/DuBois-Manor-DuBois-Manor-1-by-Diana-Baxter.pdf
    • http://loaminoo.linkpc.net/1097091095095094/Fragile-Crystal-Rubies-and-Rivalries-The-Crystal-Fragments-Trilogy-2-by-M-J-Lawless.pdf
    • http://loaminoo.linkpc.net/2095092097096096/Refracted-Crystal-Diamonds-and-Desire-The-Crystal-Fragments-Trilogy-3-by-M-J-Lawless.pdf
    • http://loaminoo.linkpc.net/5095099095091097/Zelda-and-the-Crystal-Comb-The-Crystal-Adventures-3-by-R-W-Mitchell.pdf
    • http://loaminoo.linkpc.net/9095091094097/Crystal-Promise-The-Shattered-Crystal-1-by-James-Funfer.pdf
    • http://loaminoo.linkpc.net/2090093098097090/Zelda-and-the-Crystal-Slippers-The-Crystal-Adventures-1-by-R-W-Mitchell.pdf
    • http://loaminoo.linkpc.net/4093093098094093/Crystal-Traveler-Crystal-Message-Chronicles-1-by-R-B-Breighton.pdf
    • http://loaminoo.linkpc.net/1095099096095090/Crystal-Line-Crystal-Singer-3-by-Anne-McCaffrey.pdf
    • http://loaminoo.linkpc.net/2094095094099098/Sissy-In-Law-by-Kylie-Gable.pdf
    • http://loaminoo.linkpc.net/2094095092095097/A-Sissy-Story-by-Shaun-Putaine.pdf
    • http://loaminoo.linkpc.net/1091097090094091097/The-Sultan-s-Sissy-by-Melinda-Streng.pdf
    • http://loaminoo.linkpc.net/4093096092099094/My-Extraordinary-Ordinary-Life-by-Sissy-Spacek.pdf
    • http://loaminoo.linkpc.net/1097091095095094/Fragile-Crystal-Rubies