Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2abe5b487b9e5be…

MALICIOUS

PDF

15.2 KB Created: 2019-05-03 14:35:41 +01:00 Authoring application: mPDF 5.7
MD5: 6aa8f0f2aa4fe716404830e427fc615e SHA-1: 3527470cfa3ddb33f9b3dc5c306537b0cde717ab SHA-256: c2abe5b487b9e5be442b0e2d4d6aaebaf4a452ea858af11febf411d1025f15e4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the same domain, suggesting a link farm or SEO manipulation tactic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic indicate a potential for malicious redirection or content delivery. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the immediate intent beyond link distribution.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4096095091092093/The-Wicked-Wallflower-Bad-Boys-amp-Wallflowers-1-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/3095092092098097/What-a-Wallflower-Wants-Bad-Boys-amp-Wallflowers-3-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/3090092092099096/Wallflower-Gone-Wild-Bad-Boys-amp-Wallflowers-2-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/4097096095099094/The-Bad-Boy-Billionaire-What-a-Girl-Wants-Bad-Boys-amp-Wallflowers-3-5-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/4097096095099095/The-Bad-Boy-Billionaire-s-Girl-Gone-Wild-Bad-Boys-amp-Wallflowers-2-5-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/1091094096098094/A-Wallflower-Christmas-Wallflowers-4-5-by-Lisa-Kleypas.pdf
    • http://loaminoo.linkpc.net/2090098092096096/At-The-Billionaire-s-Wedding-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/2099091090099096/The-Tattooed-Duke-The-Writing-Girls-3-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/2090094092094095/It-s-Hard-Out-Here-for-a-Duke-Keeping-Up-with-the-Cavendishes-4-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/3092097090096098/Three-Schemes-and-a-Scandal-The-Writing-Girls-3-5-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/4092093098094093/Lady-Bridget-s-Diary-Keeping-Up-with-the-Cavendishes-1-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/3094099090091093/Lady-Bridget-s-Diary-Keeping-Up-with-the-Cavendishes-1-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/3094099090095093/Chasing-Lady-Amelia-Keeping-Up-with-the-Cavendishes-2-by-Maya-Rodale.pdf
    • http://loaminoo.linkpc.net/4096095099097093/The-Vixen-Wicked-Wallflowers-2-by-Christi-Caldwell.pdf
    • http://loaminoo.linkpc.net/8092091095/Wicked-and-the-Wallflower-The-Bareknuckle-Bastards-1-by-Sarah-MacLean.pdf
    • http://loaminoo.linkpc.net/3092097096095097/Wicked-and-the-Wallflower-The-Bareknuckle-Bastards-1-by-Sarah-MacLean.pdf
    • http://loaminoo.linkpc.net/3090092099098095/Sasha-The-Wallflower-The-Wallflower-Series-1-by-R-J-Fletcher.pdf
    • http://loaminoo.linkpc.net/1091091097095090/The-Wallflower-Vol-1-The-Wallflower-1-by-Tomoko-Hayakawa.pdf
    • http://loaminoo.linkpc.net/6097095094092097/The-Wallflower-Vol-27-The-Wallflower-27-by-Tomoko-Hayakawa.pdf
    • http://loaminoo.linkpc.net/2091099098097096/To-Wed-a-Wicked-Highlander-Bad-Boys-of-the-Highlands-3-by-Victoria-Roberts.pdf
    • http://loaminoo.linkpc.net/3092097090096098/Three-Scheme