Malicious PDF — malware analysis report

Static analysis result for SHA-256 b63c4f1bbeec5f75…

MALICIOUS

PDF

19.5 KB Created: 2019-05-03 06:23:33 +01:00 Authoring application: mPDF 5.7
MD5: 44fafee128ff6b53fd8b0a313a342f25 SHA-1: 562e17c9bab863097c4ce02ab2ffa85b978f4c88 SHA-256: b63c4f1bbeec5f7550567246a1c0149902846492886e1346d9dcbed726cab343
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents hosted on the 'loaminoo.linkpc.net' domain. While the individual linked PDFs are marked as benign, the sheer volume and structure suggest a link farm or SEO manipulation tactic, which can be a precursor to malicious activity or used to distribute unwanted content. No scripts were extracted, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091096093096092095/Endymion-a-Tale-of-Greece-by-Henry-B-Henry-Beck-1813-1874-Hirst.pdf
    • http://loaminoo.linkpc.net/1091096093096092091/Endymion---A-Tale-of-Greece-by-Henry-Beck-Hirst.pdf
    • http://loaminoo.linkpc.net/8098094097091092/Henry-Kuttner-Masters-of-the-Weird-Tale-by-Henry-Kuttner.pdf
    • http://loaminoo.linkpc.net/7098090091096094/Henry-Wadsworth-Longfellow-s-Evangeline-A-Tale-of-Acadie-by-Henry-Wadsworth-1807-1882-Longfellow.pdf
    • http://loaminoo.linkpc.net/7098090091096093/Henry-Wadsworth-Longfellow-s-Evangeline-A-Tale-of-Acadie-by-Henry-Wadsworth-1807-1882-Longfellow.pdf
    • http://loaminoo.linkpc.net/3097097092096097/Henry-The-Beck-Brothers-1-by-Andria-Large.pdf
    • http://loaminoo.linkpc.net/1090090090096096099/Gift-of-the-Magi-A-Christmas-Musical-Based-on-O-Henry-s-Story-by-O-Henry.pdf
    • http://loaminoo.linkpc.net/3093099098098092/The-tudor-brief-part1-Henry-VII-and-Henry-VIII-by-Carol-Derbyshire.pdf
    • http://loaminoo.linkpc.net/7091091099096096/O-Henry-s-the-Gift-of-the-Magi-Original-Ill-by-Shelley-Freshman-by-O-Henry.pdf
    • http://loaminoo.linkpc.net/9092096094/Henry-amp-Eva-and-the-Castle-on-the-Cliff-Henry-amp-Eva-1-by-Andrea-Portes.pdf
    • http://loaminoo.linkpc.net/1099090094094095/O-Henry-La-Carte-The-Gift-of-the-Magi-and-Other-Favorites-by-O-Henry.pdf
    • http://loaminoo.linkpc.net/7098090091090093/Evangeline-A-Tale-of-Acadie-by-Henry-Wadsworth-Longfellow.pdf
    • http://loaminoo.linkpc.net/9092097098094091/Henry-Dared-to-Live-by-Henry-J-Seiler.pdf
    • http://loaminoo.linkpc.net/1098097091096094/Henry-and-Beezus-Henry-2-by-Beverly-Cleary.pdf
    • http://loaminoo.linkpc.net/6095092096092090/This-Is-of-Aucassin-and-Nicolette-a-Song-Tale-of-True-Lovers-by-M-Henry.pdf
    • http://loaminoo.linkpc.net/1091092092096098093/The-Great-Roll-of-the-Pipe-for-the-Twenty-Sixth-Year-of-the-Reign-of-King-Henry-the-Third-A-D-1241-1242-Now-First-Printed-from-the-Original-in-the-Custody-of-the-Right-Hon-the-Master-of-the-Rolls-by-Henry-Lewin-Cannon.pdf
    • http://loaminoo.linkpc.net/1093097095091095/The-Best-Short-Stories-of-O-Henry-by-O-Henry.pdf
    • http://loaminoo.linkpc.net/3093098097095091/Love-Letters-of-Henry-VIII-to-Anne-Boleyn-by-Henry-VIII-of-England.pdf
    • http://loaminoo.linkpc.net/1095093091095097/Lieutenant-Henry-Gallant-The-Henry-Gallant-Saga-2-by-H-Peter-Alesso.pdf
    • http://loaminoo.linkpc.net/2099098095097095/Voodoo-Tales-The-Ghost-Stories-of-Henry-S-Whitehead-by-Henry-S-Whitehead.pdf
    • http://loaminoo.linkpc.net/30