Malicious PDF — malware analysis report

Static analysis result for SHA-256 bfed080c41625e46…

MALICIOUS

PDF

13.9 KB Created: 2019-05-03 05:08:58 +01:00 Authoring application: mPDF 5.7
MD5: 7641996aec2f37b932d6a533acc13daa SHA-1: 4c0135b1d5b5b6e4c72b422461e420e9f984ad11 SHA-256: bfed080c41625e464ea31bc3baeddc292625f23f0b8dee59341285da68f5d0d9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a link farm, indicating a large number of embedded URLs. The document body confirms the presence of numerous links, many of which point to book titles hosted on the 'loaminoo.linkpc.net' domain. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely for SEO spam or to redirect users to malicious sites. No scripts were extracted, and the document body content is heavily obfuscated, limiting further analysis.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9098095093090095/The-Island-of-Doctor-Moreau-by-H-G-Wells-Illustrated-Delphi-Parts-Edition-H-G-Wells-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/7094092096097092/Roughing-Up-the-Suspect-by-Vida-M-Suede.pdf
    • http://loaminoo.linkpc.net/1093094096095093/Roughing-the-Passer-ESC-Mavericks-1-by-Alison-Hendricks.pdf
    • http://loaminoo.linkpc.net/1092092096090093/Roughing-the-Kicker-Saints-and-Sinners-1-by-Eden-Butler.pdf
    • http://loaminoo.linkpc.net/3097092098094094/Susanna-Moodie-Roughing-It-in-the-Bush-by-Carol-Shields.pdf
    • http://loaminoo.linkpc.net/5097099097099096/The-Time-Machine-By-H-G-Wells---Illustrated-Bonus-Free-Audiobook-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/3098090097098092/Crusade-for-Justice-The-Autobiography-of-Ida-B-Wells-by-Ida-B-Wells-Barnett.pdf
    • http://loaminoo.linkpc.net/6095091098099098/The-Time-Machine-Herbert-George-Wells-by-H-G-Wells.pdf
    • http://loaminoo.linkpc.net/5092095099093/Three-Wells-of-the-Sea-Three-Wells-of-the-Sea-1-by-Terry-Madden.pdf
    • http://loaminoo.linkpc.net/1094096094094093/All-of-It-by-Kim-Holden.pdf
    • http://loaminoo.linkpc.net/3097096094098090/Skeptic-by-Holden-Scott.pdf
    • http://loaminoo.linkpc.net/1096097098091090/Gus-Bright-Side-2-by-Kim-Holden.pdf
    • http://loaminoo.linkpc.net/2096090096095092/The-Red-Heir-by-Holden-R-Johnson.pdf
    • http://loaminoo.linkpc.net/1092090091092093/Three-Imaginary-Boys-by-J-T-Holden.pdf
    • http://loaminoo.linkpc.net/1097092090091091/The-Full-Monty-by-Wendy-Holden.pdf
    • http://loaminoo.linkpc.net/1090099093097099094/Dolly-Vardon-by-Anton-Holden.pdf
    • http://loaminoo.linkpc.net/1097097097093/The-Holden-Age-of-Hollywood-by-Phil-Brody.pdf
    • http://loaminoo.linkpc.net/1090093092096095092/Tchaikovsky-A-Biography-by-Anthony-Holden.pdf
    • http://loaminoo.linkpc.net/8093091099096098/l-cole-des-maris-by-Holden-Wendy.pdf
    • http://loaminoo.linkpc.net/3091097093091095/The-River-Sorrow-by-Craig-Holden.pdf
    • http://loaminoo.linkpc.net/3097