Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f350004f0c9239b…

MALICIOUS

PDF

19.2 KB Created: 2019-04-30 05:21:56 +01:00 Authoring application: mPDF 5.7
MD5: 94e143b3555129ae39439db8ec85a70b SHA-1: 2f27d2d4bf020f467e3864895fd86c63d9b64f2c SHA-256: 9f350004f0c9239b994107b8970bdc9703de9e357206d18cc9f98715299ccba0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1204.002 Malicious Link

The PDF document was identified as malicious due to a critical heuristic firing for a large number of embedded external links. These links, predominantly pointing to PDF files with numeric slugs, suggest a link farm or SEO manipulation tactic. While the URLs themselves are marked as benign, the sheer volume and structure indicate a potential for malicious redirection or content delivery. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7090094094094099/Martha-Inc-The-Incredible-Story-of-Martha-Stewart-Living-Omnimedia-by-Christopher-M-Byron.pdf
    • http://loaminoo.linkpc.net/1091094097093097096/Tragedy-and-the-Philosophical-Life-A-Response-to-Martha-Nussbaum-by-Martha-C-Beck.pdf
    • http://loaminoo.linkpc.net/2093095091094099/Martha-Martha-The-Good-Part-by-Teresa-R-Jones.pdf
    • http://loaminoo.linkpc.net/3090094097096/The-Golden-Rule-by-Sherrill-S-Cannon.pdf
    • http://loaminoo.linkpc.net/1095097092091094/Karda-Adalta-Vol-I-by-Sherrill-Nilson.pdf
    • http://loaminoo.linkpc.net/3090094098094/Mice-amp-Spiders-amp-Webs-Oh-My-by-Sherrill-S-Cannon.pdf
    • http://loaminoo.linkpc.net/3096091091092099/A-Dime-Is-a-Sign-Poems-of-Love-and-Loss-by-Sherrill-S-Cannon.pdf
    • http://loaminoo.linkpc.net/1092091095098096/Braehead-Three-Founding-Families-In-Nineteenth-Century-Canada-by-Sherrill-MacLaren.pdf
    • http://loaminoo.linkpc.net/5096096093094096/Exercises-in-Dedication-of-George-Finley-Bovard-Administration-Auditorium-Hoose-Hall-of-Philosophy-and-Stowell-Hall-of-Education-University-of-Southern-California-by-University-of-Southern-California.pdf
    • http://loaminoo.linkpc.net/3090098093094090/Martha-Stewart-s-Cakes-Our-First-Ever-Book-of-Bundts-Loaves-Layers-Coffee-Cakes-and-more-by-Martha-Stewart.pdf
    • http://loaminoo.linkpc.net/3091091091098094/Martha-Stewart-s-Menus-for-Entertaining-by-Martha-Stewart.pdf
    • http://loaminoo.linkpc.net/1095096096095/The-Saturday-Night-Special-And-Other-Guns-with-which-Americans-won-the-West-Protected-Bootleg-Franchises-Slew-Wildlife-Robbed-Countless-Banks-Shot-with-the-Debate-Over-Continuing-Same-by-Robert-Sherrill.pdf
    • http://loaminoo.linkpc.net/4095092093092095/Ruins-by-Kevin-J-Anderson.pdf
    • http://loaminoo.linkpc.net/1098092095090091/The-Ruins-by-Scott-B-Smith.pdf
    • http://loaminoo.linkpc.net/9095090099098/Behind-the-Ruins-by-Michael-Lane.pdf
    • http://loaminoo.linkpc.net/6096096098092/A-God-in-Ruins-by-Kate-Atkinson.pdf
    • http://loaminoo.linkpc.net/5090091093092098/The-Ruins-of-Us-by-Keija-Parssinen.pdf
    • http://loaminoo.linkpc.net/1096090099097099/A-Rose-Among-the-Ruins-by-Ariel-Tachna.pdf
    • http://loaminoo.linkpc.net/3091098091097097/Ruins-Terra-by-Eric-T-Reynolds.pdf
    • http://loaminoo.linkpc.net/7095094098097096/Breakfast-in-the-Ruins-by-Michael-Moorcock.pdf
    • http://loaminoo.linkpc.net/5096096093094096/Exercises-in-Dedication-of-George-Finley-Bovard-Administration-Auditorium-Hoose-Hall-