Malicious PDF — malware analysis report

Static analysis result for SHA-256 b738f7ad608d7ef2…

MALICIOUS

PDF

19.4 KB Created: 2019-04-30 02:52:06 +01:00 Authoring application: mPDF 5.7
MD5: 84651c39983f44a5b976f9fdc79fe3db SHA-1: 097a1747a6704c7cb744cb842e05fe710790d98d SHA-256: b738f7ad608d7ef2201caf11ee78e60d19033894433318c8517f204c58fcf975
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on 'loaminoo.linkpc.net'. While the URLs themselves are marked as confirmed benign, the sheer volume and structure suggest a potential SEO manipulation or a link farm intended to distribute malicious content or redirect users. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095096094091094/Borrowed-Light-by-Anna-Fienberg.pdf
    • http://loaminoo.linkpc.net/7094093097090/The-Magnificent-Nose-and-Other-Marvels-by-Anna-Fienberg.pdf
    • http://loaminoo.linkpc.net/1091093097095091096/The-Great-Big-Enormous-Book-of-Tashi-Tashi-1-16-by-Anna-Fienberg.pdf
    • http://loaminoo.linkpc.net/1091093097095090096/Tashi-and-the-Ghosts-Tashi-3-by-Anna-Fienberg.pdf
    • http://loaminoo.linkpc.net/1091093097095090099/Tashi-and-the-Big-Stinker-Tashi-7-by-Anna-Fienberg.pdf
    • http://loaminoo.linkpc.net/8097099090093/The-16th-Round-From-Number-1-Contender-to-Number-45472-by-Rubin-Carter.pdf
    • http://loaminoo.linkpc.net/7091090093098094/Color-by-Number-Butterflies-30-fun-amp-relaxing-color-by-number-projects-to-engage-amp-entertain-by-Walter-Foster-Creative-Team.pdf
    • http://loaminoo.linkpc.net/7091090093099093/Color-by-Number-Mandalas-30-fun-amp-relaxing-color-by-number-projects-to-engage-amp-entertain-by-Walter-Foster-Creative-Team.pdf
    • http://loaminoo.linkpc.net/7091090093099095/Color-by-Number-Flowers-30-fun-amp-relaxing-color-by-number-projects-to-engage-amp-entertain-by-Walter-Foster-Creative-Team.pdf
    • http://loaminoo.linkpc.net/7091090093099090/Color-by-Number-Dogs-30-fun-amp-relaxing-color-by-number-projects-to-engage-amp-entertain-by-Walter-Foster-Creative-Team.pdf
    • http://loaminoo.linkpc.net/6091097092099091/Anna-of-All-the-Russias-A-Life-of-Anna-Akhmatova-by-Elaine-Feinstein.pdf
    • http://loaminoo.linkpc.net/7091092091093097/Ask-Anna-Advice-for-the-Furry-and-Forlorn-by-Anna-Koontz.pdf
    • http://loaminoo.linkpc.net/9095098092095094/Anna-Simons-Meisterin-Der-Schriftkunst-1871-1951-Ausstellung-in-Der-Universitats--Und-Stadtbibliothek-Anlasslich-Der-125-Wiederkehr-Ihres-Geburts-by-Anna-Simons.pdf
    • http://loaminoo.linkpc.net/3095095094093094/After-Anna-After-Anna-1-by-Theda-Black.pdf
    • http://loaminoo.linkpc.net/2096099090091096/Number-11-by-Jonathan-Coe.pdf
    • http://loaminoo.linkpc.net/9098094092090095/Number-10-by-Sue-Townsend.pdf
    • http://loaminoo.linkpc.net/3098092097094098/Anna-Banana-and-the-Little-Lost-Kitten-Anna-Banana-5-by-Anica-Mrose-Rissi.pdf
    • http://loaminoo.linkpc.net/4095092092096090/The-Number-on-Her-Arm-by-Courtney-Tisch.pdf
    • http://loaminoo.linkpc.net/1091096096090098/Number-One-Sam-by-Greg-Pizzoli.pdf
    • http://loaminoo.linkpc.net/2092097095098092/I-Am-Not-a-Number-by-Jenny-Kay-Dupuis.pdf