Malicious PDF — malware analysis report

Static analysis result for SHA-256 af8cc4d3c8e8ac14…

MALICIOUS

PDF

14.2 KB Created: 2019-04-30 18:38:26 +01:00 Authoring application: mPDF 5.7
MD5: 47ad22d19b8dbba8d524be49600b68a0 SHA-1: 6f9279b73e7d1a91ed613fa310e83b1944b38bee SHA-256: af8cc4d3c8e8ac14818d76512ce2833594cbd8c4ba8396119a0ec3c64a699bde
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing indicating a large number of external links, suggesting a link farm or SEO manipulation tactic. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a potential for hosting malicious content or redirecting users to malicious sites. No scripts were extracted from this sample, limiting further analysis of its direct payload delivery mechanism.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.ne
    • http://loaminoo.linkpc.net/2090093091097096/Desire-in-the-Desert-by-Mary-Lyons.pdf
    • http://loaminoo.linkpc.net/7091095094096096/Bound-by-Desire-Brandon-Morgan-5-by-Rosemary-Rogers.pdf
    • http://loaminoo.linkpc.net/2091093099098095/Missy-s-First-Mission-Missy-the-Werecat-3-by-P-G-Allison.pdf
    • http://loaminoo.linkpc.net/4096091093092093/Missy-s-Misadventure-Missy-the-Werecat-4-by-P-G-Allison.pdf
    • http://loaminoo.linkpc.net/4092092091093096/Missy-Piggle-Wiggle-and-the-Whatever-Cure-Missy-Piggle-Wiggle-1-by-Ann-M-Martin.pdf
    • http://loaminoo.linkpc.net/2091093098093095/Missy-the-Werecat-Missy-the-Werecat-1-by-P-G-Allison.pdf
    • http://loaminoo.linkpc.net/3099090094098098/Bound-by-Honor-Bound-by-Love-Native-American-Romance-3-by-Ruth-Ann-Nordin.pdf
    • http://loaminoo.linkpc.net/7095092093090097/Bound-by-Vengeance-Ravage-MC-Bound-3-by-Ryan-Michele.pdf
    • http://loaminoo.linkpc.net/2099099091098096/Picture-Her-Bound-Bayou-Bound-1-by-Sidney-Bristol.pdf
    • http://loaminoo.linkpc.net/7095092092090099/Bound-by-Affliction-Ravage-MC-Bound-4-by-Ryan-Michele.pdf
    • http://loaminoo.linkpc.net/4098092090099092/Forever-Bound-Bound-by-Darkness-1-by-Leanne-Scott.pdf
    • http://loaminoo.linkpc.net/4091090097093090/Bound-by-Destiny-Ravage-MC-Bound-5-by-Ryan-Michele.pdf
    • http://loaminoo.linkpc.net/2098092090094092/Creation-of-Desire-Desire-Oklahoma-3-by-Leah-Brooke.pdf
    • http://loaminoo.linkpc.net/2095091097092092/Rules-Of-Desire-Desire-Oklahoma-4-by-Leah-Brooke.pdf
    • http://loaminoo.linkpc.net/4091091095099095/Blade-s-Desire-Desire-Oklahoma-2-by-Leah-Brooke.pdf
    • http://loaminoo.linkpc.net/3098096091099099/Submission-to-Desire-Desire-Oklahoma-7-by-Leah-Brooke.pdf
    • http://loaminoo.linkpc.net/2095099098098095/Bound-by-Love-The-Bound-Series-2-by-S-E-Gilchrist.pdf
    • http://loaminoo.linkpc.net/1092095095096098/Bound-by-Prophecy-Bound-3-by-Stormy-Smith.pdf
    • http://loaminoo.linkpc.net/7092097092099093/Bound-Bound-Hearts-Book-1-by-S-N-Garza.pdf
    • http://loaminoo.linkpc.net/8096097093092/Bound-in-Darkness-Bound-2-by-Cynthia-Eden.pdf