Malicious PDF — malware analysis report

Static analysis result for SHA-256 910dc2cb8d6e6ea8…

MALICIOUS

PDF

18.9 KB Created: 2019-05-04 14:16:55 +01:00 Authoring application: mPDF 5.7
MD5: 87fc907c133d5b93fd254493ed0f87c7 SHA-1: 53abd19655eb554238703fde2617f7aa8e28f5c9 SHA-256: 910dc2cb8d6e6ea8805c926793f990661cfcb2eb625456f1c6d0307e69fe834a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.n
    • http://loaminoo.linkpc.net/3099098092097097/The-Winter-People-The-Winter-People-1-by-Rebekah-L-Purdy.pdf
    • http://loaminoo.linkpc.net/1097099098097092/The-Winter-People-The-Winter-People-1-by-Rebekah-L-Purdy.pdf
    • http://loaminoo.linkpc.net/1099095097091092/The-Summer-Marked-The-Winter-People-2-by-Rebekah-L-Purdy.pdf
    • http://loaminoo.linkpc.net/2095099098091090/The-Summer-Marked-The-Winter-People-2-by-Rebekah-L-Purdy.pdf
    • http://loaminoo.linkpc.net/7097098096095/The-Winter-People-by-Phyllis-A-Whitney.pdf
    • http://loaminoo.linkpc.net/2097096095098091/Winter-s-End-by-Rebekah-Lyn.pdf
    • http://loaminoo.linkpc.net/4099094099092091/Winter-s-End-Seasons-of-Faith-2-by-Rebekah-Lyn.pdf
    • http://loaminoo.linkpc.net/2093091097091/Wandering-Through-Winter-A-Naturalist-s-Record-of-a-20-000-Mile-Journey-Through-the-North-American-Winter-by-Edwin-Way-Teale.pdf
    • http://loaminoo.linkpc.net/2094096091090099/The-War-Against-Miss-Winter-Rosie-Winter-1-by-Kathryn-Miller-Haines.pdf
    • http://loaminoo.linkpc.net/2092090092097096/Winter-s-Scars-The-Forsaken-Winter-s-Saga-5-by-Karen-Luellen.pdf
    • http://loaminoo.linkpc.net/1095095097090099/Winter-s-Wrath-Sacrifice-Winter-s-Saga-3-by-Karen-Luellen.pdf
    • http://loaminoo.linkpc.net/4096094091098/A-Witch-in-Winter-Winter-Trilogy-1-by-Ruth-Warburton.pdf
    • http://loaminoo.linkpc.net/9092091099096/The-Road-to-Winter-Winter-1-by-Mark-Smith.pdf
    • http://loaminoo.linkpc.net/1098090093091096/The-Romeo-Club-by-Rebekah-L-Purdy.pdf
    • http://loaminoo.linkpc.net/2097092096090099/The-11-Laws-of-Likability-Relationship-Networking-Because-People-Do-Business-with-People-They-Like-by-Michelle-Tillis-Lederman.pdf
    • http://loaminoo.linkpc.net/7094097099094095/Value-People-to-People-Another-way-to-craft-brands-and-do-business-by-Christophe-Fauconnier.pdf
    • http://loaminoo.linkpc.net/4095091099092092/Daisy-and-the-Front-Man-Backstage-Pass-3-by-Rebekah-L-Purdy.pdf
    • http://loaminoo.linkpc.net/7095099093091090/Daily-Routine-What-Makes-the-Difference-between-Highly-Successful-People-and-Unsuccessful-People---Become-the-Master-of-Your-Life-by-Andrew-Gump.pdf
    • http://loaminoo.linkpc.net/1090098090090097091/Rotes-Meer-Der-achte-Fall-f-r-Erik-Winter-Ein-Erik-Winter-Krimi-by-ke-Edwardson.pdf
    • http://loaminoo.linkpc.net/1090098098096092098/Hush-Little-Baby-A-Jefferson-Winter-Thriller-0-6-The-Jefferson-Winter-Chronicles-2-by-James-Carol.pdf