Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf80dd268322159b…

MALICIOUS

PDF

17.4 KB Created: 2019-04-30 04:19:57 +01:00 Authoring application: mPDF 5.7
MD5: 7e5fbe83e8f850f55d18ae1d433bcb91 SHA-1: 0a6d0f94e1ea264722731ba58bc09125615f54cb SHA-256: bf80dd268322159b523e2b96aa790b36d1568b14f9f1cb321fa0db8301e49d0f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links predominantly point to book titles hosted on loaminoo.linkpc.net. While the URLs themselves are currently classified as benign, the sheer volume and pattern suggest a potential SEO manipulation or a lure to download further malicious content. No scripts were extracted from this sample, limiting the ability to determine a more specific attack vector or payload.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4091099098092092/Redemption-The-Cain-Chronicles-2-by-A-D-Seeley.pdf
    • http://loaminoo.linkpc.net/1091093092096098/The-Mark-of-Cain-The-Cain-Chronicles-1-by-A-D-Seeley.pdf
    • http://loaminoo.linkpc.net/2098090095099099/Of-Wings-and-Wolves-Seasons-of-the-Moon-Cain-Chronicles-6-by-S-M-Reine.pdf
    • http://loaminoo.linkpc.net/1091095098094091/Dark-Redemption-The-Darkness-Chronicles-2-by-Elle-Bright.pdf
    • http://loaminoo.linkpc.net/2098097092098099/Beautiful-Redemption-Caster-Chronicles-4-by-Kami-Garcia.pdf
    • http://loaminoo.linkpc.net/3099096093090090/Redemption-Royal-Blood-Chronicles-7-by-Elizabeth-Loraine.pdf
    • http://loaminoo.linkpc.net/1093095093098095/Blood-Moon-Harvest-Seasons-of-the-Moon-Cain-Chronicles-2-by-S-M-Reine.pdf
    • http://loaminoo.linkpc.net/7099094090092/New-Moon-Summer-Seasons-of-the-Moon-Cain-Chronicles-1-by-S-M-Reine.pdf
    • http://loaminoo.linkpc.net/5098090097093/The-Cain-Casey-Series-Volume-1-Cain-Casey-1-3-by-Ali-Vali.pdf
    • http://loaminoo.linkpc.net/7092091097093097/Perc-e-nue-8-R-demption-Huiti-me-partie-R-demption-by-Scarlett-Edwards.pdf
    • http://loaminoo.linkpc.net/8090090094096099/Redemption-s-Edge-Redemption-Mountain-1-by-Shirleen-Davies.pdf
    • http://loaminoo.linkpc.net/3097096092091099/Redemption-Ransom-Retribution-Redemption-1-3-by-R-K-Ryals.pdf
    • http://loaminoo.linkpc.net/6094098097093099/-Mi-golah-li-geM--ulah-From-Exile-to-Redemption-Volume-1-Chassidic-teachings-of-the-Lubavitcher-Rebbe-Rabbi-Menachem-M-Schneerson-and-the-preceding-Rebbeim-of-Chab-ad-on-the-future-redemption-and-the-coming-of-Mashiach-by-Eliyahu-Friedman.pdf
    • http://loaminoo.linkpc.net/4094098096091/Redemption-Redemption-1-by-Karen-Kingsbury.pdf
    • http://loaminoo.linkpc.net/2091098099091093/Redemption-Redemption-1-by-Lindsey-Gray.pdf
    • http://loaminoo.linkpc.net/2097094091097095/Rapture-1-by-R-J-Seeley.pdf
    • http://loaminoo.linkpc.net/1094097090093098/Nightwing-Vol-1-Better-Than-Batman-by-Tim-Seeley.pdf
    • http://loaminoo.linkpc.net/2098095096091098/Seeley-and-the-Grantuff-by-Linda-Bond.pdf
    • http://loaminoo.linkpc.net/4093092097099092/Hack-Slash-My-First-Maniac-by-Tim-Seeley.pdf
    • http://loaminoo.linkpc.net/6096097093093096/Revival-T03-Si-loin-de-chez-nous-by-Tim-Seeley.pdf