Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ac8eaece6319a32…

MALICIOUS

PDF

21.0 KB Created: 2019-05-01 20:33:44 +01:00 Authoring application: mPDF 5.7
MD5: 921213aa9c21918258eb146eac089f2f SHA-1: 82743ef8cb9c9b6d5f7fc65abbf65e95ae243844 SHA-256: 8ac8eaece6319a328ed7ba599ad721e83b87843881b7be3d9e7768964afdb82f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links pointing to external PDF documents. The heuristic PDF_SEO_LINK_FARM indicates a link farm, and the URLs are hosted on a suspicious domain, loaminoo.linkpc.net. The document body is heavily obfuscated but contains references to these URLs, suggesting a lure to download or view these linked documents. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090098090092099097/Winning-at-Poker-Essential-Hints-amp-Tips-by-Dave-Scharf.pdf
    • http://loaminoo.linkpc.net/3097099097097094/Play-Poker-Like-the-Pros-The-greatest-poker-player-in-the-world-today-reveals-his-million-dollar-winning-strategies-to-the-most-popular-tournament-home-and-online-games-by-Phil-Hellmuth.pdf
    • http://loaminoo.linkpc.net/3098095099099091/365-Down-To-Earth-Gardening-Hints-And-Tips-by-Susan-McClure.pdf
    • http://loaminoo.linkpc.net/3095091091092091/Winning-at-Internet-Poker-for-Dummies-by-Mark-Harlan.pdf
    • http://loaminoo.linkpc.net/4090090092092098/Austerity-Dad-Handy-Hints-and-Tips-for-the-family-on-a-budget-The-Stay-At-Home-Dad-Diaries-Book-2-by-Jason-Ayres.pdf
    • http://loaminoo.linkpc.net/5090090097092092/Devilfish-The-Life-Times-of-a-Poker-Legend-by-Dave-Ulliott.pdf
    • http://loaminoo.linkpc.net/2095098097096096/I-Will-Survive-Tips-and-Hints-to-Help-You-Survive-in-this-Zombie-Infested-World-Survive-1-by-Dana-Burkey.pdf
    • http://loaminoo.linkpc.net/5095096097091/How-To-Win-Football-Bets-Easily-Every-Time-Top-Secrets-Tips-And-Best-Strategies-For-Winning-Big-by-B-Guru.pdf
    • http://loaminoo.linkpc.net/6090098098096095/Bonsai-101-Essential-Tips-by-Harry-Tomlinson.pdf
    • http://loaminoo.linkpc.net/2099093095096090/Nanna-s-Travel-Tips-by-Dave-Cornford.pdf
    • http://loaminoo.linkpc.net/1091094096090094/The-4-1-1-on-Reinventing-You-Essential-Tips-for-Knowing-What-You-Want---And-Getting-It-by-Michele-Sfakianos.pdf
    • http://loaminoo.linkpc.net/1090096094092098093/Draw-Poker-Odds-The-Mathematics-of-Classical-Poker-by-Catalin-Barboianu.pdf
    • http://loaminoo.linkpc.net/1094093093090096/Machiavellian-Poker-Strategy-How-to-Play-Like-a-Prince-and-Rule-the-Poker-Table-by-David-Apostolico.pdf
    • http://loaminoo.linkpc.net/5092097098090093/Cesar-Millan-s-Short-Guide-to-a-Happy-Dog-98-Essential-Tips-and-Techniques-by-Cesar-Millan.pdf
    • http://loaminoo.linkpc.net/1090092095099097091/Tips-for-Running-18-Interesting-Tips-for-Runners-by-Alan-Seel.pdf
    • http://loaminoo.linkpc.net/1092097098095094/Winning-Ace-The-Winning-Ace-1-by-Tracie-Delaney.pdf
    • http://loaminoo.linkpc.net/7094097093096099/Poker-Face-Poker-Face-1-by-Adriana-Law.pdf
    • http://loaminoo.linkpc.net/1090098090094094096/Grace-amp-the-Ice-Prince-by-J-L-Scharf.pdf
    • http://loaminoo.linkpc.net/1090098090094091091/Scharf-auf-den-Lehrer-by-Laura-Abensberg.pdf
    • http://loaminoo.linkpc.net/7098091093098092/Dave-s-Dinners-A-Fresh-Approach-to-Home-Cooked-Meals-by-Dave-Lieberman.pdf