Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c2a2c1660176db5…

MALICIOUS

PDF

19.6 KB Created: 2019-04-30 08:29:03 +01:00 Authoring application: mPDF 5.7
MD5: 6e749e6edae4d5747ca8c8c3a821be3e SHA-1: 6204e71b6db37e96a6bf9e6ac2d0a029b93c1ccf SHA-256: 7c2a2c1660176db531703b4c54bb3be736968d147ebdc25019705f77d994f1f1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm, with the dominant host being loaminoo.linkpc.net. While the extracted URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent to drive traffic or potentially distribute further payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092093091091092/Firing-Line-by-Richard-Holmes.pdf
    • http://loaminoo.linkpc.net/1090094098096091090/Memoirs-Sixty-Years-on-the-Firing-Line-by-Arthur-Krock.pdf
    • http://loaminoo.linkpc.net/6094091099092090/Hard-Line-by-Richard-Perle.pdf
    • http://loaminoo.linkpc.net/8094098092093096/The-Sherlock-Holmes-Illustrated-Omnibus-The-Adventures-of-Sherlock-Holmes-the-Memoirs-of-Sherlock-Holmes-the-Hound-of-the-Baskervilles-the-Return-of-Sherlock-Holmes-A-Facsimile-of-the-by-Arthur-Conan-Doyle.pdf
    • http://loaminoo.linkpc.net/4093097090095097/Footsteps-Adventures-of-a-Romantic-Biographer-by-Richard-Holmes.pdf
    • http://loaminoo.linkpc.net/1099091093091093/Marlborough-England-s-Fragile-Genius-by-Richard-Holmes.pdf
    • http://loaminoo.linkpc.net/6096096092092096/The-Vatican-Cameos-A-Sherlock-Holmes-Adventure-by-Richard-T-Ryan.pdf
    • http://loaminoo.linkpc.net/2091092092093/The-Age-of-Wonder-How-the-Romantic-Generation-Discovered-the-Beauty-and-Terror-of-Science-by-Richard-Holmes.pdf
    • http://loaminoo.linkpc.net/4090090099099093/Tommy-The-British-Soldier-on-the-Western-Front-1914-1918-by-Richard-Holmes.pdf
    • http://loaminoo.linkpc.net/4090092094090090/The-World-at-War-The-Landmark-Oral-History-from-the-Previously-Unpublished-Archives-by-Richard-Holmes.pdf
    • http://loaminoo.linkpc.net/4095091098091094/A-Firing-Offense-by-George-Pelecanos.pdf
    • http://loaminoo.linkpc.net/1092098092095098/Becoming-Holmes-The-Boy-Sherlock-Holmes-His-Final-Case-The-Boy-Sherlock-Holmes-6-by-Shane-Peacock.pdf
    • http://loaminoo.linkpc.net/1091092093094094095/Raku-Glass---A-Kiln-Firing-Process-by-Boyce-Lundstrom.pdf
    • http://loaminoo.linkpc.net/1090090092099092/Firing-Heather-The-Life-and-Times-of-Nellie-McClung-by-Mary-E-Hallett.pdf
    • http://loaminoo.linkpc.net/8094097095092090/Hamlet-Easiest-to-read-with-line-by-line-interpretations-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/2099099094091092/A-Line-Drawn-The-Line-Trilogy-3-by-Catherine-Taylor.pdf
    • http://loaminoo.linkpc.net/6091097093094092/Erasing-the-Line-Toeing-the-Line-3-by-Allyson-Lindt.pdf
    • http://loaminoo.linkpc.net/2099099094090093/A-Line-Crossed-The-Line-Trilogy-2-by-Catherine-Taylor.pdf
    • http://loaminoo.linkpc.net/4092093097096093/The-Finest-Line-The-Line-Trilogy-1-by-Catherine-Taylor.pdf
    • http://loaminoo.linkpc.net/2099096096094098/Drawing-the-Line-The-Line-2-by-Kimberly-Kincaid.pdf