Malicious PDF — malware analysis report

Static analysis result for SHA-256 35479ed15081969a…

MALICIOUS

PDF

16.8 KB Created: 2019-05-02 05:10:00 +01:00 Authoring application: mPDF 5.7
MD5: 47a79f042b766622271b5c76159aff1b SHA-1: f91bdc30324985e77aefc87adf8db698697bc680 SHA-256: 35479ed15081969a7876648433081f98add7daa95b4f494a332ed3e24f5dce1a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a 'PDF_SEO_LINK_FARM' heuristic. These URLs point to various book titles, suggesting a potential SEO manipulation or content hosting scheme. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic indicate a malicious intent to direct traffic or host potentially harmful content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.lin
    • http://loaminoo.linkpc.net/3090099099090090/The-Wicked-Years-Complete-Collection-Wicked-Son-of-a-Witch-A-Lion-Among-Men-and-Out-of-Oz-by-Gregory-Maguire.pdf
    • http://loaminoo.linkpc.net/3095099093098/Son-of-a-Witch-The-Wicked-Years-2-by-Gregory-Maguire.pdf
    • http://loaminoo.linkpc.net/2095091097092096/Son-of-a-Witch-The-Wicked-Years-2-by-Gregory-Maguire.pdf
    • http://loaminoo.linkpc.net/3095097097090093/Wicked-The-Life-and-Times-of-the-Wicked-Witch-of-the-West-by-Gregory-Maguire.pdf
    • http://loaminoo.linkpc.net/2099095091094092/Every-Witch-Way-But-Wicked-Wicked-Witches-of-the-Midwest-2-by-Amanda-M-Lee.pdf
    • http://loaminoo.linkpc.net/1094098096097099/Wicked-The-Complete-Series-Wicked-1-4-by-Lily-Graison.pdf
    • http://loaminoo.linkpc.net/5092090096095/Wicked-Series-Complete-Box-Set-Wicked-1-3-by-M-S-Parker.pdf
    • http://loaminoo.linkpc.net/3095096097096098/Pure-Wicked-Wicked-Lovers-9-5-1001-Dark-Nights-25-by-Shayla-Black.pdf
    • http://loaminoo.linkpc.net/1094094095094/The-Wicked-Wicked-Ladies-in-the-Haunted-House-by-Mary-Chase.pdf
    • http://loaminoo.linkpc.net/1094096097094091/Wicked-Favor-The-Wicked-Horse-Vegas-1-by-Sawyer-Bennett.pdf
    • http://loaminoo.linkpc.net/1097091091095096/Wicked-Desires-Wicked-Affairs-1-by-Eliza-Lloyd.pdf
    • http://loaminoo.linkpc.net/3092096097090095/Wicked-Lust-The-Wicked-Horse-2-by-Sawyer-Bennett.pdf
    • http://loaminoo.linkpc.net/2090091093093092/Wicked-My-Love-Wicked-Little-Secrets-2-by-Susanna-Ives.pdf
    • http://loaminoo.linkpc.net/3098093097090093/Wicked-Bond-The-Wicked-Horse-5-by-Sawyer-Bennett.pdf
    • http://loaminoo.linkpc.net/4099091099097094/Wicked-2-Legacy-amp-Spellbound-Wicked-3-4-by-Nancy-Holder.pdf
    • http://loaminoo.linkpc.net/4095095093092091/Wicked-Lies-Wicked-2-Colony-4-by-Lisa-Jackson.pdf
    • http://loaminoo.linkpc.net/3099090096090095/Lady-Gone-Wicked-Wicked-Secrets-2-by-Elizabeth-Bright.pdf
    • http://loaminoo.linkpc.net/1093094093/Wicked-Fall-The-Wicked-Horse-1-by-Sawyer-Bennett.pdf
    • http://loaminoo.linkpc.net/3093091090091090/The-Chronicles-of-Narnia-and-Philosophy-The-Lion-the-Witch-and-the-Worldview-by-Gregory-Bassham.pdf
    • http://loaminoo.linkpc.net/4094097092098098/Any-Witch-Way-You-Can-Wicked-Witches-of-the-Midwest-1-by-Amanda-M-Lee.pdf