Malicious PDF — malware analysis report

Static analysis result for SHA-256 b9a96776bb192b4b…

MALICIOUS

PDF

25.5 KB Created: 2019-05-01 17:05:08 +01:00 Authoring application: mPDF 5.7
MD5: 698c8e2c79323c121d6b657eaae182cc SHA-1: 18768e94eb6e03adb97e922ef1c410c4196af5fb SHA-256: b9a96776bb192b4ba9d235853957ff333a6e69dad664eed80bc1659d805c97f3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a link farm with 32 external links, primarily pointing to URLs with numeric slugs. While the extracted URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to redirect users to harmful content. No scripts were extracted from this sample, and the document body was unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.ne
    • http://loaminoo.linkpc.net/8096095098090090/Orpheus-in-Paris-Offenbach-and-the-Paris-of-His-Time-by-Siegfried-Kracauer.pdf
    • http://loaminoo.linkpc.net/7099096090098095/Schienenverkehr-Paris-Bahnhof-in-Paris-Metro-Paris-Strassenbahn-Paris-Metrolinie-7bis-Chemin-de-Fer-de-Petite-Ceinture-Ratp-by-Quelle-Wikipedia.pdf
    • http://loaminoo.linkpc.net/4094095096094092/The-Golden-Moments-of-Paris-A-Guide-to-the-Paris-of-the-1920s-by-John-Baxter.pdf
    • http://loaminoo.linkpc.net/4094095091092098/Walks-in-Hemingway-s-Paris-A-Guide-to-Paris-for-the-Literary-Traveler-by-No-l-Riley-Fitch.pdf
    • http://loaminoo.linkpc.net/1091097095095094/Paris-Paris-Journey-into-the-City-of-Light-by-David-Downie.pdf
    • http://loaminoo.linkpc.net/8090094095091097/How-Paris-Became-Paris-The-Invention-of-the-Modern-City-by-Joan-DeJean.pdf
    • http://loaminoo.linkpc.net/6090091097093/The-Glow-of-Paris-The-Bridges-of-Paris-at-Night-by-Gary-Zuercher.pdf
    • http://loaminoo.linkpc.net/2093098095098091/Judgment-of-Paris-California-vs-France-and-the-Historic-1976-Paris-Tasting-That-Revolutionized-Wine-by-George-M-Taber.pdf
    • http://loaminoo.linkpc.net/5092099095093092/When-Paris-Sizzled-The-1920s-Paris-of-Hemingway-Chanel-Cocteau-Cole-Porter-Josephine-Baker-and-Their-Friends-by-Mary-McAuliffe.pdf
    • http://loaminoo.linkpc.net/8096095098090094/Siegfried-Kracauer-An-Introduction-by-Gertrud-Koch.pdf
    • http://loaminoo.linkpc.net/8096095099090096/Siegfried-Kracauers-Jacques-Offenbach-Biographie-Geschichte-Zeitgeschichte-by-Harald-Reil.pdf
    • http://loaminoo.linkpc.net/8096095099091091/Frankfurter-Turmhauser-Ausgewahlte-Feuilletons-1906-30-by-Siegfried-Kracauer.pdf
    • http://loaminoo.linkpc.net/8096095098098091/Culture-in-the-Anteroom-The-Legacies-of-Siegfried-Kracauer-by-Gerd-Gem-39-unden.pdf
    • http://loaminoo.linkpc.net/8096095099090097/Reluctant-Skeptic-Siegfried-Kracauer-and-the-Crises-of-Weimar-Culture-by-Harry-T-Craver.pdf
    • http://loaminoo.linkpc.net/8093096094097096/Nouvelles-Annales-de-Paris-Jusqu-au-Regne-de-Hugues-Capet-On-Y-Joint-Le-Po-me-d-Abbon-Sur-Le-Fameux-Si-ge-de-Paris-Par-Les-Normans-En-885-amp-886-Beaucoup-Plus-Correct-Que-Dans-Aucune-Des-ditions-Pr-c-d-ntes-by-Michel-Toussaint-Chretien-Duplessis.pdf
    • http://loaminoo.linkpc.net/4098096097091097/The-Last-Time-I-Saw-Paris-by-Elizabeth-Adler.pdf
    • http://loaminoo.linkpc.net/6097099092095098/Le-Paris-um-Ou-Tableau-Actuel-de-Paris-Ouvrage-Indispensable-Pour-Conna-tre-Et-Visiter-En-Peu-de-Temps-Ce-Qu-il-Y-a-de-Curieux-Dans-Cette-Capitale-Et-Aux-Environs-Antiquit-s-Edifices-Mus-es-Manufactures-Spectacles-On-Y-Trouvera-Les-Embellissem-by-J-Francois-C-Blanvillain.pdf
    • http://loaminoo.linkpc.net/4098090099099098/The-Paris-Review-Interviews-II-Wisdom-from-the-World-s-Literary-Masters-by-The-Paris-Review.pdf
    • http://loaminoo.linkpc.net/2099096099094096/This-Time-Forever-Glebe-Point-1-by-Patricia-Paris.pdf
    • http://loaminoo.linkpc.net/4097097096091091/Time-Was-Soft-There-A-Paris-Sojourn-at-Shakespeare-amp-Co-by-Jeremy-Mercer.pdf