Malicious PDF — malware analysis report

Static analysis result for SHA-256 baa43870dccb6310…

MALICIOUS

PDF

15.5 KB Created: 2019-04-30 05:46:21 +01:00 Authoring application: mPDF 5.7
MD5: 7468d47ae243a461e501c4465ace80c9 SHA-1: 97e77565fb297a9821d2ae038583f3ff3d6825c6 SHA-256: baa43870dccb6310e259b1b77556d159150c95d51909543aa70048d57cd1f558
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

This PDF file contains a link farm with 21 external PDF links, all hosted on the same domain. The heuristic PDF_SEO_LINK_FARM indicates this is a technique to artificially inflate search engine rankings or distribute content. While the URLs themselves are marked as benign, the sheer volume and structure suggest a malicious intent to drive traffic or potentially host malicious content disguised as legitimate documents. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099099095095095/Isolde-Queen-of-the-Western-Isle-Tristan-and-Isolde-1-by-Rosalind-Miles.pdf
    • http://loaminoo.linkpc.net/6091092094092099/Tristan-and-Isolde-A-Casebook-by-Joan-Tasker-Grimbert.pdf
    • http://loaminoo.linkpc.net/6091092094093094/Tristan-amp-Isolde-The-Warrior-and-the-Princess-a-British-Legend-by-Jeff-Limke.pdf
    • http://loaminoo.linkpc.net/6091092094098096/Drustan-the-Wanderer-A-Novel-Based-on-the-Legend-of-Tristan-and-Isolde-by-Anna-Taylor.pdf
    • http://loaminoo.linkpc.net/3097092096091099/The-Nibelungen-Tradition-An-Encyclopedia-by-Francis-G-Gentry.pdf
    • http://loaminoo.linkpc.net/1094092090095091/A-Companion-to-Middle-High-German-Literature-to-the-14th-Century-by-Francis-G-Gentry.pdf
    • http://loaminoo.linkpc.net/6091092094093092/Richard-Wagner-Tristan-Und-Isolde-by-Richard-Wagner.pdf
    • http://loaminoo.linkpc.net/6091092094090094/The-Stories-of-Isolde-Her-Master-s-Domain-The-Stories-of-Isolde-1-by-Belle-de-Jour.pdf
    • http://loaminoo.linkpc.net/5097097093093090/The-unholy-Books-of-Tristan-Wrangler-Tristan-Wrangler-Series-Book-1-by-Don-Both.pdf
    • http://loaminoo.linkpc.net/7091094098097092/The-Centenary-Corbiere-Poems-and-Prose-of-Tristan-Corbiere-by-Tristan-Corbi-re.pdf
    • http://loaminoo.linkpc.net/6091092094098098/the-Book-of-Isolde-by-J-J-Circe.pdf
    • http://loaminoo.linkpc.net/5090098095095097/Moonlight-and-Shadow-by-Isolde-Martyn.pdf
    • http://loaminoo.linkpc.net/1090099095090098090/Die-Welt-f-llt-in-den-Wald-Familiengeschichten-by-Isolde-S-ess-Morat.pdf
    • http://loaminoo.linkpc.net/6091097092098092/The-Francis-Chan-Collection-Crazy-Love-Forgotten-God-Erasing-Hell-and-Multiply-by-Francis-Chan.pdf
    • http://loaminoo.linkpc.net/5090091098096092/Apache-Caress-by-Georgina-Gentry.pdf
    • http://loaminoo.linkpc.net/3090097090093096/Cheyenne-Song-by-Georgina-Gentry.pdf
    • http://loaminoo.linkpc.net/8094091098096091/Warrior-s-Heart-by-Georgina-Gentry.pdf
    • http://loaminoo.linkpc.net/6098096095092090/Apache-Tears-by-Georgina-Gentry.pdf
    • http://loaminoo.linkpc.net/3093097098098090/Replacing-Gentry-by-Julie-N-Ford.pdf
    • http://loaminoo.linkpc.net/1096095098094099/Churn-Book-I-of-III-by-J-AUSTIN-GENTRY.pdf
    • http://loaminoo.linkpc.net/6091092094098098/the-Book-