Malicious PDF — malware analysis report

Static analysis result for SHA-256 83fd6e2aa3b273a8…

MALICIOUS

PDF

19.7 KB Created: 2019-05-02 01:42:35 +01:00 Authoring application: mPDF 5.7
MD5: 7f7e81e91549df6ec7fc1125074adab8 SHA-1: cd563e419ae75c2142c99dfe4e13a62c7985cacc SHA-256: 83fd6e2aa3b273a8790cc4306a1da93f2a277fcc5a4ec07474233c37a85b4b6d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this is an attempt to manipulate search engine results or distribute content through a large number of links. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.ne
    • http://loaminoo.linkpc.net/1091097093099092091/The-Living-Mala-by-Elizabeth-D-Vartanian.pdf
    • http://loaminoo.linkpc.net/1091099095092098093/Yoga-Mala-The-Seminal-Treatise-and-Guide-from-the-Living-Master-of-Ashtanga-Yoga-by-Sri-K-Pattabhi-Jois.pdf
    • http://loaminoo.linkpc.net/4098095099090095/Living-In-Living-Out-African-American-Domestics-in-Washington-D-C-1910-1940-by-Elizabeth-Clark-Lewis.pdf
    • http://loaminoo.linkpc.net/9098096095/Big-Magic-Creative-Living-Beyond-Fear-by-Elizabeth-Gilbert.pdf
    • http://loaminoo.linkpc.net/4099096091/The-Telomere-Effect-The-New-Science-of-Living-Younger-by-Elizabeth-Blackburn.pdf
    • http://loaminoo.linkpc.net/2097095095091092/Living-Revision-A-Writer-s-Craft-as-Spiritual-Practice-by-Elizabeth-Jarrett-Andrew.pdf
    • http://loaminoo.linkpc.net/4099090092097099/Bless-This-Love-by-S-M-Mala.pdf
    • http://loaminoo.linkpc.net/8095095099095092/Relative-Strangers-by-S-M-Mala.pdf
    • http://loaminoo.linkpc.net/4098099098099097/The-Problem-of-Getting-Rich-Quik-part-two-by-S-M-Mala.pdf
    • http://loaminoo.linkpc.net/3098094097095099/A-mala-de-Hana---Uma-Hist-ria-Real-by-Karen-Levine.pdf
    • http://loaminoo.linkpc.net/4093099094096092/Mala-of-Love-108-Luminous-Poems-by-Ravi-Nathwani.pdf
    • http://loaminoo.linkpc.net/1091097093097093098/See-Saw-Connections-Between-Japanese-Art-Then-and-Now-by-Ivan-Vartanian.pdf
    • http://loaminoo.linkpc.net/1091097093097094098/Neuroscience-of-Decision-Making-by-Oshin-Vartanian.pdf
    • http://loaminoo.linkpc.net/1091097093099091094/Na-Poroge-Dvadtsat-Pervogo-Vremia-Pamiat-My-by-Arkadii-Vartanian.pdf
    • http://loaminoo.linkpc.net/9090092098097090/Living-Grim-The-Grim-Trilogy-2-by-Elizabeth-Holloway.pdf
    • http://loaminoo.linkpc.net/1091097093099091093/Paleo-Slow-Cooker-Healthy-Gluten-Free-Meals-the-Easy-Way-by-Arsy-Vartanian.pdf
    • http://loaminoo.linkpc.net/2095096092093098/The-Temptation-of-Elizabeth-Tudor-Elizabeth-I-Thomas-Seymour-and-the-Making-of-a-Virgin-Queen-by-Elizabeth-Norton.pdf
    • http://loaminoo.linkpc.net/1091097093098094090/Perspectives-in-Psychopharmacotherapy-International-Symposium-of-Org-Who-amp-Menarini-International-Foundation-by-F-Vartanian.pdf
    • http://loaminoo.linkpc.net/1091097093097094096/Nobuyoshi-Araki-The-Banquet-Books-on-Books-No-15-by-Ivan-Vartanian.pdf
    • http://loaminoo.linkpc.net/8098099093098091/Living-in-DC-An-Insider-s-Guide-How-to-Get-a-Job-and-Make-the-Most-of-Living-in-the-Nation-s-Capital-by-Kate-McFadyen.pdf