Malicious PDF — malware analysis report

Static analysis result for SHA-256 9db9f05a699b6a0a…

MALICIOUS

PDF

16.0 KB Created: 2019-05-02 22:44:08 +01:00 Authoring application: mPDF 5.7
MD5: 83eccf860d8430bc6a124eb8240e49f0 SHA-1: a4002dfeb41e7de4b33c84a21e6fea3181748c04 SHA-256: 9db9f05a699b6a0a697ce7c914c64b9cbfa44e60a201e8b494b6c01fb1dba41e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links pointing to external PDF files hosted on the loaminoo.linkpc.net domain. This suggests a link farm or a method to distribute further malicious content. The heuristic PDF_SEO_LINK_FARM specifically identified this behavior. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9091092097/The-Geography-of-Lost-Things-by-Jessica-Brody.pdf
    • http://loaminoo.linkpc.net/3090098092097095/Jane-Brody-s-Good-Food-Book-Living-the-High-Carbohydrate-Way-by-Jane-E-Brody.pdf
    • http://loaminoo.linkpc.net/4095094095099097/Unremembered-Unremembered-1-by-Jessica-Brody.pdf
    • http://loaminoo.linkpc.net/3092093090097091/Unremembered-Unremembered-1-by-Jessica-Brody.pdf
    • http://loaminoo.linkpc.net/2098092094098095/A-Reaper-s-Tale---The-Undecided-by-Adam-Slade.pdf
    • http://loaminoo.linkpc.net/1098094098093092/My-Coyote-Ugly-Life-My-Life-1-by-Jessica-Spoon.pdf
    • http://loaminoo.linkpc.net/5097090097098098/Money-Habitudes-How-to-Be-Rich-in-Life-and-Love-by-Jessica-Pool.pdf
    • http://loaminoo.linkpc.net/8092091091091091/Life-Abundant-a-30-day-devotional-for-Latter-day-Saint-Women-by-Jessica-Coup-.pdf
    • http://loaminoo.linkpc.net/7095093096091/The-Secret-Life-of-a-Witch-Mystic-Willow-Bay-Witches-1-by-Jessica-Sorensen.pdf
    • http://loaminoo.linkpc.net/8097094097/Imperfect-Courage-Live-a-Life-of-Purpose-by-Leaving-Comfort-and-Going-Scared-by-Jessica-Honegger.pdf
    • http://loaminoo.linkpc.net/3095090098095091/Virtue-and-Vice-by-Kimberly-Brody.pdf
    • http://loaminoo.linkpc.net/1090090099099092/Brody-Circle-Eight-2-by-Emma-Lang.pdf
    • http://loaminoo.linkpc.net/2092090099091/Yukon-Audit-a-C-E-Brody-Novel-by-Ken-Baird.pdf
    • http://loaminoo.linkpc.net/1097097097093/The-Holden-Age-of-Hollywood-by-Phil-Brody.pdf
    • http://loaminoo.linkpc.net/5095096097091094/Shadows-of-the-Moon-Black-Wolf-Agency-2-by-Jessica-Musso-Jessica-Lupo-.pdf
    • http://loaminoo.linkpc.net/7097092099092/Jessica-Jessica-Trouble-Sweet-Valley-Kids-59-by-Francine-Pascal.pdf
    • http://loaminoo.linkpc.net/4098097099097/The-Wedding-of-Antanasia-Jessica-Packwood-and-Lucius-Valeriu-Vladescu-Jessica-1-5-by-Beth-Fantaskey.pdf
    • http://loaminoo.linkpc.net/8094092095099/Brody-s-Ghost-Volume-1-by-Mark-Crilley.pdf
    • http://loaminoo.linkpc.net/8094095095097/Brody-s-Ghost-Volume-2-by-Mark-Crilley.pdf
    • http://loaminoo.linkpc.net/1091092094094098098/Conversations-with-Tibor-by-Brody-Drew-McVittie.pdf
    • http://loaminoo.linkpc.net/8097094097/Imperfect-Courage-Live-a-Life-of-Purpose-by-L