Malicious PDF — malware analysis report

Static analysis result for SHA-256 c116c8c0a7082e25…

MALICIOUS

PDF

16.3 KB Created: 2019-05-02 21:08:29 +01:00 Authoring application: mPDF 5.7
MD5: 8f76645824deea655bc58dfbb488eca8 SHA-1: 3db3d98dddda636e49d0e84ed489382d035f2aef SHA-256: c116c8c0a7082e25c1496865c03dedcaf0174d5c9ba698d89078884877a85c78
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO poisoning or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external link farm, and the document body confirms the presence of these links. The primary intent appears to be directing users to a large collection of linked PDFs hosted on the 'loaminoo.linkpc.net' domain, likely as a lure or to distribute further content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095099098092095/Wings-of-Vengeance-Hidden-Wings-5-by-Cameo-Renae.pdf
    • http://loaminoo.linkpc.net/4097091098097099/Gilded-Wings-Hidden-Wings-4-by-Cameo-Renae.pdf
    • http://loaminoo.linkpc.net/4092099094096/Hidden-Wings-Hidden-Wings-1-by-Cameo-Renae.pdf
    • http://loaminoo.linkpc.net/6095098093096098/Butterfly-wings-and-dragonfly-wings-Guardian-Fairy-Book-7-by-Anastasia-Ducret.pdf
    • http://loaminoo.linkpc.net/4098094095093093/ARV-3-The-After-Light-Saga-1-by-Cameo-Renae.pdf
    • http://loaminoo.linkpc.net/5095099090092/Guarding-Eden-Midway-1-by-Cameo-Renae.pdf
    • http://loaminoo.linkpc.net/3098095091098092/On-Silent-Wings-Wings-1-by-Don-Conroy.pdf
    • http://loaminoo.linkpc.net/3093091092095091/Hidden-Truths-The-Hidden-Series-1-by-Nicole-Colville.pdf
    • http://loaminoo.linkpc.net/1099090092092092/Hidden-by-Lies-Hidden-Hearts-1-by-Rachel-Caid.pdf
    • http://loaminoo.linkpc.net/9095099090097/Hidden-Love-Hidden-Truth-by-V-L-Yoakum.pdf
    • http://loaminoo.linkpc.net/5097099093091/HIDDEN-MICKEY-3-Wolf-The-Legend-of-Tom-Sawyer-s-Island-Hidden-Mickey-3-by-Nancy-Temple-Rodrigue.pdf
    • http://loaminoo.linkpc.net/1097099099094091/What-Is-Hidden-What-Is-Hidden-1-by-Lauren-Skidmore.pdf
    • http://loaminoo.linkpc.net/5091099098090/HIDDEN-MICKEY-Sometimes-Dead-Men-DO-Tell-Tales-Hidden-Mickey-1-by-Nancy-Temple-Rodrigue.pdf
    • http://loaminoo.linkpc.net/3091090098098096/Clipped-Wings-Clipped-Wings-1-by-Helena-Hunting.pdf
    • http://loaminoo.linkpc.net/6092095097099/Violet-Wings-Violet-Wings-1-by-Victoria-Hanley.pdf
    • http://loaminoo.linkpc.net/1099099095097097/Wings-A-Fairy-Tale-Fairy-Wings-1-by-E-D-Baker.pdf
    • http://loaminoo.linkpc.net/9092091091091/HIDDEN-MICKEY-ADVENTURES-1-Peter-and-the-Wolf-Hidden-Mickey-Adventures-1-by-Nancy-Temple-Rodrigue.pdf
    • http://loaminoo.linkpc.net/2092098099099092/Hidden-Talents-Hidden-Talents-1-by-Claire-Cray.pdf
    • http://loaminoo.linkpc.net/2092098090094092/Wings-by-Mikhail-Kuzmin.pdf
    • http://loaminoo.linkpc.net/3092090098096091/Wings-of-Change-by-Jim-Murdoch.pdf
    • http://loaminoo.linkpc.net/50