Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9bed99aa0bd3076…

MALICIOUS

PDF

15.8 KB Created: 2019-05-01 17:57:12 +01:00 Authoring application: mPDF 5.7
MD5: 8fbd4c0c37d1d0cdf79b2ae494fcfc87 SHA-1: 7a198d76506ab8f41af65e332d079875d2a2d04e SHA-256: a9bed99aa0bd3076e76cd7e4d7c7316af0da889db5ec6f8956142d15ec1cd7e4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a heuristic firing for a link farm, with 21 embedded external URLs. These URLs predominantly point to the 'loaminoo.linkpc.net' domain and appear to be structured as book downloads. The attack pattern is likely a lure to direct users to potentially malicious content or phishing pages disguised as legitimate downloads.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3092095091094095/Irish-Thoroughbred-Irish-Hearts-1-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/6091095090099/Heart-of-the-Sea-Gallaghers-of-Ardmore-Irish-Trilogy-3-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/8093092093096/Tears-of-the-Moon-Gallaghers-of-Ardmore-Irish-Trilogy-2-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/9098092093091096/Tranen-van-de-maan-Gallaghers-of-Ardmore-Irish-Trilogy-2-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/9095093095091093/Srce-mora-Gallaghers-of-Ardmore-Irish-Trilogy-3-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/1091097098094092098/Samantha-s-Irish-Luck-Thoroughbred-66-by-Joanna-Campbell.pdf
    • http://loaminoo.linkpc.net/3098093095091098/The-Irish-Devil-Irish-Eyes-1-Irish-Eyes-Duo-1-by-Donna-Fletcher.pdf
    • http://loaminoo.linkpc.net/3094090096092096/Fingal-O-Reilly-Irish-Doctor-Irish-Country-8-by-Patrick-Taylor.pdf
    • http://loaminoo.linkpc.net/4096090097093098/Murder-at-an-Irish-Wedding-Irish-Village-Mystery-2-by-Carlene-O-39-Connor.pdf
    • http://loaminoo.linkpc.net/4093090097091095/Thicker-Than-Water-Coming-of-Age-Stories-by-Irish-amp-Irish-American-Writers-by-Gordon-Snell.pdf
    • http://loaminoo.linkpc.net/8092091093096094/Irish-Dance-Riverdance-the-Pirate-Queen-Irish-Stepdance-Ceilidh-Clare-Lancers-Set-Feis-Celtic-Tiger-Live-Garryowen-Sean-Nos-Dance-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/2091090095092098/An-Irish-Country-Village-Irish-Country-2-by-Patrick-Taylor.pdf
    • http://loaminoo.linkpc.net/2098098090098097/An-Irish-Country-Girl-Irish-Country-4-by-Patrick-Taylor.pdf
    • http://loaminoo.linkpc.net/5099099095095098/S-duit-malgr-lui-Nora-Roberts-by-Nora-Roberts.pdf
    • http://loaminoo.linkpc.net/4090093090094095/The-Irish-Giant-by-G-Frankcom.pdf
    • http://loaminoo.linkpc.net/2098092095099090/The-Irish-R-M-by-Edith-Somerville.pdf
    • http://loaminoo.linkpc.net/1091099096092098/The-Irish-Cowboy-by-D-W-Ulsterman.pdf
    • http://loaminoo.linkpc.net/2097098097098096/In-the-Irish-Brigade-by-G-A-Henty.pdf
    • http://loaminoo.linkpc.net/9097093097095098/Luck-of-the-Irish-by-Liz-Gavin.pdf
    • http://loaminoo.linkpc.net/4094093092098098/Who-s-Irish-Stories-by-Gish-Jen.pdf
    • http://loaminoo.linkpc.net/8092091093096094/Irish-Dance-Riverdance-the-