Malicious PDF — malware analysis report

Static analysis result for SHA-256 93394db3d0a1ae9d…

MALICIOUS

PDF

15.4 KB Created: 2019-04-30 03:16:06 +01:00 Authoring application: mPDF 5.7
MD5: 8fab33675daee8c6a284cdceadbed35c SHA-1: 4aae5166da17f995251c068005f1dd234a7b20d8 SHA-256: 93394db3d0a1ae9db8e9caa65094cc6048c80d1390a66e8ee0c8b50dbd5f28ae
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, forming a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates that these links are likely intended to direct users to external content, potentially for SEO manipulation or to host malicious payloads. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent to redirect users. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.n
    • http://loaminoo.linkpc.net/4097096094097097/Inside-Marine-One-Four-U-S-Presidents-One-Proud-Marine-and-the-World-s-Most-Amazing-Helicopter-by-Ray-L-39-Heureux.pdf
    • http://loaminoo.linkpc.net/3099096093092097/Marine-With-Benefits-Always-a-Marine-16-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/2092095090096099/A-Candle-for-a-Marine-Always-a-Marine-18-by-Heather-Long.pdf
    • http://loaminoo.linkpc.net/6098094099093099/Warfighting-Marine-Corps-Doctrinal-Publication-1-by-U-S-Marine-Corps.pdf
    • http://loaminoo.linkpc.net/6091095098093094/Marine-I-by-David-Monnery.pdf
    • http://loaminoo.linkpc.net/9093092094091094/The-Marine-by-Rudy-Josephs.pdf
    • http://loaminoo.linkpc.net/2094099098096092/Claimed-by-the-Marine-by-Dez-Burke.pdf
    • http://loaminoo.linkpc.net/1096091092099096/Last-Marine-Standing-Heroes-2-by-R-J-Scott.pdf
    • http://loaminoo.linkpc.net/2092095091097095/A-Marine-for-Christmas-by-Makenna-Jameison.pdf
    • http://loaminoo.linkpc.net/4096092098090091/Montana-Marine-by-Debra-Parmley.pdf
    • http://loaminoo.linkpc.net/6098094099091090/The-Reminiscences-of-a-Marine-by-John-A-Lejeune.pdf
    • http://loaminoo.linkpc.net/1091096093098098099/Oceanside-Marine-Kendalls-4-by-Jennifer-Ann.pdf
    • http://loaminoo.linkpc.net/3099094098099092/Marry-Me-Marine-by-Rogenna-Brewer.pdf
    • http://loaminoo.linkpc.net/6098094099094090/Make-Mine-A-Marine-by-Julie-Miller.pdf
    • http://loaminoo.linkpc.net/1091099096097092096/The-Superstar-Marine-Bodyguards-1-by-Patricia-Logan.pdf
    • http://loaminoo.linkpc.net/1091094097093/Her-Temporary-Hero-Once-a-Marine-2-by-Jennifer-Apodaca.pdf
    • http://loaminoo.linkpc.net/7090092094097097/La-face-crash-e-de-Marine-Le-Pen-by-Richard-Malka.pdf
    • http://loaminoo.linkpc.net/6099093098095094/Kick-the-Dealer-Not-the-Tires-by-Mark-Marine.pdf
    • http://loaminoo.linkpc.net/1091099093094/Coming-Undone-Marine-4-by-Susan-Andersen.pdf
    • http://loaminoo.linkpc.net/5094095091096090/Combat-Barbie-Always-a-Marine-11-by-Heather-Long.pdf