Malicious PDF — malware analysis report

Static analysis result for SHA-256 ad8f9557ed00bc81…

MALICIOUS

PDF

20.7 KB Created: 2019-05-02 21:08:46 +01:00 Authoring application: mPDF 5.7
MD5: 6aa0128430dbc8fa60117e26f9195459 SHA-1: 5852a89582cc3d4ad1d2a8976f2ae96a8cd67004 SHA-256: ad8f9557ed00bc81d77ee5a60f81f1e3ce36f660f094e573f6339d33bc2d2aca
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents hosted on loaminoo.linkpc.net. While the URLs themselves are marked as benign, the sheer volume and structure suggest a potential SEO manipulation or a link farm designed to distribute malicious content or redirect users to harmful sites. No scripts were extracted, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5096099094090092/Main-Event-by-James-D-Long.pdf
    • http://loaminoo.linkpc.net/5096099093093092/Yes-My-Improbable-Journey-to-the-Main-Event-of-Wrestlemania-by-Daniel-Bryan.pdf
    • http://loaminoo.linkpc.net/1090096093098091098/Urbaner-Freiraum-in-Frankfurt-Am-Main-Parkanlage-in-Frankfurt-Am-Main-Platz-in-Frankfurt-Am-Main-Strasse-in-Frankfurt-Am-Main-Zeil-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/3091093090091091/Rain-At-Main-Event-by-Rain-Fields.pdf
    • http://loaminoo.linkpc.net/2096093094094094/The-Arctic-Event-Covert-One-7-by-James-H-Cobb.pdf
    • http://loaminoo.linkpc.net/1090093094097094098/Strasse-Rhein-Main-Strasse-in-Frankfurt-Am-Main-Strasse-in-Hanau-Strasse-in-Offenbach-Am-Main-Strasse-in-Wiesbaden-Zeil-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/5090092091097094/The-Kentucky-Derby-How-the-Run-for-the-Roses-Became-America-s-Premier-Sporting-Event-by-James-C-Nicholson.pdf
    • http://loaminoo.linkpc.net/5096099095094090/Love-in-Bloom-The-Heart-of-Main-Street-1-by-Arlene-James.pdf
    • http://loaminoo.linkpc.net/1090091093091095099/Der-Traum-Vom-Fliegen-Hohepunkte-Aus-Dem-Bildarchiv-Der-Luftfahrthistorischen-Sammlung-Der-Flughafen-Frankfurt-Main-Ag-by-Petra-Wustrack-Michael-K-Flughafen-Frankfurt-Main-Benteler.pdf
    • http://loaminoo.linkpc.net/1091095095092092095/Image-Eye-And-Art-In-Calvino-Legenda-Main-Series-Legenda-Main-Series-by-Lene-Waage-Petersen.pdf
    • http://loaminoo.linkpc.net/1093090095092096/Ferney-by-James-Long.pdf
    • http://loaminoo.linkpc.net/2097096092096095/The-Lives-She-Left-Behind-by-James-Long.pdf
    • http://loaminoo.linkpc.net/4093092090098/The-Long-Legged-Fly-Lew-Griffin-1-by-James-Sallis.pdf
    • http://loaminoo.linkpc.net/9093097095092099/James-Thurber-by-Robert-Emmet-Long.pdf
    • http://loaminoo.linkpc.net/1094099099090096/Long-Knife-by-James-Alexander-Thom.pdf
    • http://loaminoo.linkpc.net/8097095096090099/Kanal-in-Bayern-Kanal-in-Munchen-Main-Donau-Kanal-Ludwig-Donau-Main-Kanal-Mittlere-Isar-Kanal-Nordmunchner-Kanalsystem-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/5096096098093/The-Long-Journey-to-Jake-Palmer-by-James-L-Rubart.pdf
    • http://loaminoo.linkpc.net/4091097094096095/Red-Car-Long-Legs-Adventures-in-California-and-Beyond-by-Jennylynd-James.pdf
    • http://loaminoo.linkpc.net/3090091090098098/Long-Hard-Ride-Rough-Riders-1-by-Lorelei-James.pdf
    • http://loaminoo.linkpc.net/3094094096092096/Long-Hard-Ride-Rough-Riders-1-by-Lorelei-James.pdf