Malicious PDF — malware analysis report

Static analysis result for SHA-256 b762f0d406c72244…

MALICIOUS

PDF

19.6 KB Created: 2019-04-30 04:39:25 +01:00 Authoring application: mPDF 5.7
MD5: 8cb790e73db513746c2cb16c279360f0 SHA-1: 8db8a5f2499e1ccd786f7c299361e978a405177c SHA-256: b762f0d406c7224452b6414f3010a054f0c12b23158be253c92ac45a25f0d3a9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on loaminoo.linkpc.net. While the URLs themselves are marked as confirmed benign, the sheer volume and structure suggest a link farm or SEO poisoning tactic, potentially used to distribute malicious content or manipulate search rankings. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3090094096094093/You-Might-as-Well-Die-Algonquin-Round-Table-2-by-J-J-Murphy.pdf
    • http://loaminoo.linkpc.net/3092091094090097/You-Might-as-Well-Die-Algonquin-Round-Table-2-by-J-J-Murphy.pdf
    • http://loaminoo.linkpc.net/3091094092099/A-Friendly-Game-of-Murder-Algonquin-Round-Table-3-by-J-J-Murphy.pdf
    • http://loaminoo.linkpc.net/6091094097096097/Bon-Bons-Bourbon-and-Bon-Mots-Stories-from-the-Algonquin-Round-Table-by-Franklin-P-Adams.pdf
    • http://loaminoo.linkpc.net/5090090098094095/The-Vicious-Circle-Mystery-and-Crime-Stories-by-Members-of-the-Algonquin-Round-Table-by-Otto-Penzler.pdf
    • http://loaminoo.linkpc.net/2093091098094099/Knights-of-the-Round-Table-by-Peter-Brimacombe.pdf
    • http://loaminoo.linkpc.net/3091091099095099/Lancelot-Knights-Of-The-Round-Table-1-by-Gwen-Rowley.pdf
    • http://loaminoo.linkpc.net/3094093091092090/Knights-of-the-Round-Table-Geraint-by-Gwen-Rowley.pdf
    • http://loaminoo.linkpc.net/1090095099097095098/Knights-of-the-Round-Table-Choose-Your-Own-Adventure-86-by-Ellen-Kushner.pdf
    • http://loaminoo.linkpc.net/3090094099092091/Norse-Romance-II-The-Knights-of-the-Round-Table-by-Marianne-E-Kalinke.pdf
    • http://loaminoo.linkpc.net/6094098090094/Young-Knights-of-the-Round-Table-The-King-s-Ransom-by-Cheryl-Carpinello.pdf
    • http://loaminoo.linkpc.net/3091099096098096/King-Arthur-and-His-Knights-of-the-Round-Table-by-Roger-Lancelyn-Green.pdf
    • http://loaminoo.linkpc.net/8090093094090/Table-Walking-at-Nighthawk-by-Carol-Darnell-Guerrero-Murphy.pdf
    • http://loaminoo.linkpc.net/6095093096092091/Three-French-Comedies-JOFFO---The-Merry-go-round-SALACROU---The-World-is-Round-FEYDEAU---Love-on-the-Rack-by-Norman-Stokle.pdf
    • http://loaminoo.linkpc.net/4091099092091095/Round-And-Round-by-Terry-Tyler.pdf
    • http://loaminoo.linkpc.net/1091098094097097090/Ruhe-in-Fetzen-Ein-Fall-f-r-Mrs-Murphy-Ein-Mrs--Murphy-Krimi-2-by-Rita-Mae-Brown.pdf
    • http://loaminoo.linkpc.net/1091098094098097092/Die-Katze-l-sst-das-Mausen-nicht-Ein-Fall-f-r-Mrs-Murphy-Ein-Mrs--Murphy-Krimi-10-by-Rita-Mae-Brown.pdf
    • http://loaminoo.linkpc.net/2093099090098090/Algonquin-by-Dion-Henderson.pdf
    • http://loaminoo.linkpc.net/8097096094092094/Die-Katze-l-sst-das-Mausen-nicht-Maus-im-Aus-Ein-Fall-f-r-Mrs-Murphy-Catch-As-Cat-Can-Tail-Of-The-Tip-Off-Mrs-Murphy-10-11-by-Rita-Mae-Brown.pdf
    • http://loaminoo.linkpc.net/1091095098097096092/Murphy-und-das-Grauen-D-monenj-ger-Murphy-by-Earl-Warren.pdf
    • http://loaminoo.linkpc.net/3091091099095099/Lancelot-Knights-Of-The-Roun