Malicious PDF — malware analysis report

Static analysis result for SHA-256 2ba84cbf7e431f23…

MALICIOUS

PDF

16.1 KB Created: 2019-05-02 17:38:44 +01:00 Authoring application: mPDF 5.7
MD5: 955df5ca511588747d4bc0f021b75e0b SHA-1: 85191e6b561348858ba710f2501c54801392e95a SHA-256: 2ba84cbf7e431f2339d90cff7cadb257dd13f22fbaca641a9dc1f07b5060d5fe
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF documents. The heuristic 'PDF_SEO_LINK_FARM' indicates this is a link farm designed to artificially inflate search engine rankings or distribute content. While the URLs themselves are marked as benign, the sheer volume and the suspicious domain suggest a malicious intent to redirect users to potentially harmful content or to engage in SEO manipulation for malicious purposes. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.link
    • http://loaminoo.linkpc.net/1091093097092099091/Every-Breath-You-Take-Billionaires-in-Disguise-Georgie-1-Rock-Stars-in-Disguise-Xan-1-by-Blair-Babylon.pdf
    • http://loaminoo.linkpc.net/3094097092090096/Every-Breath-You-Take-Billionaires-in-Disguise-Georgie-1-Rock-Stars-in-Disguise-Xan-1-by-Blair-Babylon.pdf
    • http://loaminoo.linkpc.net/4091091092092090/Burning-Bright-Billionaires-in-Disguise-Lizzy-4-by-Blair-Babylon.pdf
    • http://loaminoo.linkpc.net/1091093097094092097/Hard-Liquor-Runaway-Billionaires-3-Arthur-Duet-2-by-Blair-Babylon.pdf
    • http://loaminoo.linkpc.net/1091093097093095099/Stiff-Drink-Arthur-Duet-1-Runaway-Billionaires-2-by-Blair-Babylon.pdf
    • http://loaminoo.linkpc.net/4099097098090097/Disguise-Billionaire-Rock-Star-Romance-1-by-Bella-Love-Wins.pdf
    • http://loaminoo.linkpc.net/5094097093094/The-Best-Romance-Ever-by-Ina-Disguise.pdf
    • http://loaminoo.linkpc.net/6097093092094094/Vigilance-in-Disguise-by-M-L-Steele.pdf
    • http://loaminoo.linkpc.net/2094097090090090/Love-in-Disguise-by-Carol-Cox.pdf
    • http://loaminoo.linkpc.net/7097099099090099/Stories-for-an-Ignorant-Man-by-Ina-Disguise.pdf
    • http://loaminoo.linkpc.net/2091098095097/Essays-In-Disguise-by-Wilfrid-Sheed.pdf
    • http://loaminoo.linkpc.net/1091093097097099099/Nemesis-in-Disguise-by-Anna-J-Stewart.pdf
    • http://loaminoo.linkpc.net/2090098095093/A-Lady-in-Disguise-by-Amanda-McCabe.pdf
    • http://loaminoo.linkpc.net/4090090094099093/Duchess-in-Disguise-by-Caroline-Courtney.pdf
    • http://loaminoo.linkpc.net/1092099095090/A-Heart-In-Disguise-by-Monette-Cummings.pdf
    • http://loaminoo.linkpc.net/5092096094/Girl-in-Disguise-by-Greer-Macallister.pdf
    • http://loaminoo.linkpc.net/7090097090/Prince-in-Disguise-by-Stephanie-Kate-Strohm.pdf
    • http://loaminoo.linkpc.net/2093090090/Demons-in-Disguise-Divinicus-Nex-Chronicles-3-by-A-E-Kirk.pdf
    • http://loaminoo.linkpc.net/4096092094096093/A-Lady-in-Disguise-Daughters-of-Hampshire-3-by-Sandra-Byrd.pdf
    • http://loaminoo.linkpc.net/1091096098098/The-Devil-in-Disguise-Regency-Rogues-1-by-Stefanie-Sloane.pdf