Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5a7e82b7aba6f8e…

MALICIOUS

PDF

18.9 KB Created: 2019-04-30 04:18:01 +01:00 Authoring application: mPDF 5.7
MD5: 3e0cedb37e7d3ac844a885cb275f664e SHA-1: dea5d73d03af27c9cbcbc3f765a9289bb1d2e011 SHA-256: a5a7e82b7aba6f8ed9e64bbfb179aeda85795fd96c450fd4b4499e6525104813
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on loaminoo.linkpc.net. While the URLs themselves are marked as confirmed benign, the sheer volume and structure suggest a potential SEO manipulation or a link farm designed to distribute further malicious content or redirect users to phishing sites. No scripts were extracted, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096095098091090/Walter-by-David-Cook.pdf
    • http://loaminoo.linkpc.net/4094097093093098/A-History-of-Narrative-Film-by-David-A-Cook.pdf
    • http://loaminoo.linkpc.net/6096098094090093/A-History-of-Narrative-Film-by-David-A-Cook.pdf
    • http://loaminoo.linkpc.net/1094099094090093/Heart-of-Oak-The-Soldier-Chronicles-2-by-David-Cook.pdf
    • http://loaminoo.linkpc.net/1095091092094098/Marksman-The-Soldier-Chronicles-4-by-David-Cook.pdf
    • http://loaminoo.linkpc.net/6095096097094/Seven-Days-in-Utopia-Golf-s-Sacred-Journey-by-David-Lamar-Cook.pdf
    • http://loaminoo.linkpc.net/1095097091090098/The-Great-Ocean-Pacific-Worlds-from-Captain-Cook-to-the-Gold-Rush-by-David-Igler.pdf
    • http://loaminoo.linkpc.net/1091098097099096095/Im-Netz-des-Wachtturms---ein-Vater-k-mpft-um-seine-Kinder-Will-Cook-und-die-Wachtturmgesellschaft-by-Will-Cook.pdf
    • http://loaminoo.linkpc.net/2096097096092093/How-to-Cook-Without-a-Book-Recipes-and-Techniques-Every-Cook-Should-Know-by-Heart-by-Pam-Anderson.pdf
    • http://loaminoo.linkpc.net/3091091091090094/How-to-Cook-Everything-Fast-A-Better-Way-to-Cook-Great-Food-by-Mark-Bittman.pdf
    • http://loaminoo.linkpc.net/4093098095097092/The-Journals-of-Captain-Cook-by-James-Cook.pdf
    • http://loaminoo.linkpc.net/3090098092099091/What-to-Cook-and-How-to-Cook-It-by-Jane-Hornby.pdf
    • http://loaminoo.linkpc.net/2095095097091099/Lee-s-Adjutant-The-Wartime-Letters-of-Colonel-Walter-Herron-Taylor-1862-1865-by-Walter-H-Taylor.pdf
    • http://loaminoo.linkpc.net/2096091091098095/Tragically-I-Was-an-Only-Twin-The-Complete-Peter-Cook-by-Peter-Cook.pdf
    • http://loaminoo.linkpc.net/4098097090092099/The-Labyrinth-Memoirs-Of-Walter-Schellenberg-Hitler-s-Chief-Of-Counterintelligence-by-Walter-Schellenberg.pdf
    • http://loaminoo.linkpc.net/1091098099096096099/Walter-Benjamin-Selected-Writings-Volume-1-1913-1926-by-Walter-Benjamin.pdf
    • http://loaminoo.linkpc.net/7097090091095097/The-Voyages-of-Captain-James-Cook-The-Illustrated-Accounts-of-Three-Epic-Pacific-Voyages-by-James-Cook.pdf
    • http://loaminoo.linkpc.net/7094098097096098/Walter-Benjamin-Selected-Writings-4-1938-1940-by-Walter-Benjamin.pdf
    • http://loaminoo.linkpc.net/8092092090096099/Lady-of-the-Lake-Walter-Scott-1910-by-Walter-Scott.pdf
    • http://loaminoo.linkpc.net/1091091091096094097/Walter-Pichler-Skulpturen-Zeichnungen-Modelle-by-Walter-Pichler.pdf
    • http://loaminoo.linkpc.net/2096097096092093/H