Malicious PDF — malware analysis report

Static analysis result for SHA-256 55eef147247628fe…

MALICIOUS

PDF

20.5 KB Created: 2019-04-30 05:18:45 +01:00 Authoring application: mPDF 5.7
MD5: 43be5b1419092628d81f302bbf228360 SHA-1: c77c2a68142954543015d250840b8db97494f26c SHA-256: 55eef147247628fe0eab29b59a20817aa8fd1deeea4bc54600cde84026b93c2b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various science fiction book titles hosted on the loaminoo.linkpc.net domain. The purpose appears to be to direct users to a large collection of external websites, potentially for SEO manipulation or to host malicious content disguised as legitimate downloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.lin
    • http://loaminoo.linkpc.net/2094098099094/Asimov-s-Science-Fiction-February-1999-Asimov-s-Science-Fiction-277-by-Gardner-Dozois.pdf
    • http://loaminoo.linkpc.net/4095096096093092/Isaac-Asimov-Presents-the-Golden-Years-of-Science-Fiction-Third-Series-by-Isaac-Asimov.pdf
    • http://loaminoo.linkpc.net/3092097093090098/Space-Shuttles-Isaac-Asimov-s-Wonderful-Worlds-of-Science-Fiction-7-by-Isaac-Asimov.pdf
    • http://loaminoo.linkpc.net/2096096092094/The-Year-s-Best-Science-Fiction-First-Annual-Collection-by-Gardner-Dozois.pdf
    • http://loaminoo.linkpc.net/7098099098094/The-13-Crimes-of-Science-Fiction-by-Isaac-Asimov.pdf
    • http://loaminoo.linkpc.net/2096095090097/The-Year-s-Best-Science-Fiction-Twenty-Fifth-Annual-Collection-by-Gardner-Dozois.pdf
    • http://loaminoo.linkpc.net/2096095097094/The-Year-s-Best-Science-Fiction-Twelfth-Annual-Collection-by-Gardner-Dozois.pdf
    • http://loaminoo.linkpc.net/2096097092096/The-Year-s-Best-Science-Fiction-Twenty-Second-Annual-Collection-by-Gardner-Dozois.pdf
    • http://loaminoo.linkpc.net/6096090094097/Earth-is-Room-Enough-Science-Fiction-Tales-of-Our-Own-Planet-by-Isaac-Asimov.pdf
    • http://loaminoo.linkpc.net/7098091093099098/The-Best-Science-Fiction-of-Isaac-Asimov-by-Isaac-Asimov.pdf
    • http://loaminoo.linkpc.net/4094095096099095/Hugo-amp-Nebula-Award-Winning-Stories-from-Asimov-s-Science-Fiction-by-Sheila-Williams.pdf
    • http://loaminoo.linkpc.net/4095097091099099/Science-Fiction-by-Gaslight-A-History-and-Anthology-of-Science-Fiction-in-the-Popular-Magazines-1891-1911-by-Sam-Moskowitz.pdf
    • http://loaminoo.linkpc.net/6099096092097097/The-First-Science-Fiction-MEGAPACK-25-Modern-and-Classic-Science-Fiction-Tales-by-Robert-Silverberg.pdf
    • http://loaminoo.linkpc.net/1095095097093095/Isaac-Asimov-s-Utopias-by-Gardner-Dozois.pdf
    • http://loaminoo.linkpc.net/3094098096096098/Isaac-Asimov-s-Vampires-by-Gardner-Dozois.pdf
    • http://loaminoo.linkpc.net/4095096090095097/Science-Fiction-for-People-Who-Hate-Science-Fiction-by-Terry-Carr.pdf
    • http://loaminoo.linkpc.net/2096090090095/Fantasy-amp-Science-Fiction-May-June-2014-The-Magazine-of-Fantasy-amp-Science-Fiction-713-by-Gordon-Van-Gelder.pdf
    • http://loaminoo.linkpc.net/7092097092092093/History-Fiction-or-Science-The-dynastic-parallelism-method-Rome-Troy-Greece-The-Bible-Chronological-shifts-New-Chronology-Vol-2-History-Fiction-or-Science-Chronology-by-Anatoly-Fomenko.pdf
    • http://loaminoo.linkpc.net/1091098092098098095/The-Fiction-of-James-Tiptree-Jr-by-Gardner-Dozois.pdf
    • http://loaminoo.linkpc.net/2096096095096/The-Science-Fiction-Hall-of-Fame-Volume-One-1929-1964-Science-Fiction-Hall-of-Fame-1-by-Robert-Silverberg.pdf