Malicious PDF — malware analysis report

Static analysis result for SHA-256 c358c224efd229db…

MALICIOUS

PDF

20.3 KB Created: 2019-04-29 23:30:47 +01:00 Authoring application: mPDF 5.7
MD5: 77373edeae3c02e4d856445317e41631 SHA-1: 1b3ff33b4584fdb152e62e79a0a4eff460a93e15 SHA-256: c358c224efd229dbe335e6f1391440831e711ee0007af75316195e3c7c2a26fa
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents hosted on loaminoo.linkpc.net. The primary attack pattern observed is the distribution of these links, likely to direct users to potentially malicious content or to engage in SEO manipulation. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7094099094096095/Temptations-D-sesp-r-Le-voleur-vampire-avec-Passionn-mensonges-S-rie-Premi-re-partie-ET---Chat-D-vor---Passion-avaler-son-changeforme---De-chat-Fi-vre-de-trois---2-Livres-1-Prix-by-C-J-Olenski.pdf
    • http://loaminoo.linkpc.net/3097090094095091/Chat-Book-One-Chat-Connect-Crash-series-1-by-Nan-McCarthy.pdf
    • http://loaminoo.linkpc.net/4094093099097092/Le-Chat---Best-of-Tome-5-Le-Top-du-Chat-by-Philippe-Geluck.pdf
    • http://loaminoo.linkpc.net/7095092095099091/Le-Chat-du-Rabbin-Tu-n-auras-pas-d-autre-dieu-que-moi-Le-Chat-du-Rabbin-6-by-Joann-Sfar.pdf
    • http://loaminoo.linkpc.net/5093097099091097/ARTISANAT-AVEC-DU-RECYCLAGE-Pingouin-Olaf-Papillon-Chat-by-Christiane-Nagy-Saad.pdf
    • http://loaminoo.linkpc.net/5096096093093091/De-la-sagesse-trois-livres-by-Pierre-Charron.pdf
    • http://loaminoo.linkpc.net/6093097091096094/Chat-Room-by-Kristin-Butcher.pdf
    • http://loaminoo.linkpc.net/6093097091096095/Chat-Joe-Gunther-18-by-Archer-Mayor.pdf
    • http://loaminoo.linkpc.net/1091097093091090/Kopitiam-Chit-Chat-by-Peggy-Tan-Pek-Tao.pdf
    • http://loaminoo.linkpc.net/6093097092091094/au-chat-et-a-la-souris-by-James-Patterson.pdf
    • http://loaminoo.linkpc.net/6093097093092091/Chat-for-a-Date-by-Asma-Nadia.pdf
    • http://loaminoo.linkpc.net/5096096098093090/Un-chat-des-rues-nomm-Bob-by-James-Bowen.pdf
    • http://loaminoo.linkpc.net/7099090099097099/Attila-le-curieux-chat-voyageur-by-Christine-Lacroix.pdf
    • http://loaminoo.linkpc.net/6090091091095099/The-Chickenborough-Chit-Chat-Club-Volume-1-by-Kamouraska.pdf
    • http://loaminoo.linkpc.net/8095092097097090/Comment-appelle-t-on-un-chat-qui-HUMOUR-by-Pierre-Beno-t-de-Veron.pdf
    • http://loaminoo.linkpc.net/5093093097094094/Mon-nez-mon-chat-l-amour-et-moi-Le-Journal-intime-de-Georgia-Nicolson-1-by-Louise-Rennison.pdf
    • http://loaminoo.linkpc.net/4091090094092090/Dying-For-A-Chat-The-Communication-Breakdown-Between-Doctors-and-Patients-by-Ranjana-Srivastava.pdf
    • http://loaminoo.linkpc.net/3091090096097094/Buddha-s-Table-Thai-Feasting-Vegetarian-Style-by-Chat-Mingkwan.pdf
    • http://loaminoo.linkpc.net/6093097092097096/Chat-Room-Teri-Blake-Addison-Mystery-2-by-Linda-Hall.pdf
    • http://loaminoo.linkpc.net/7091099091090092/Chatdicted-1-0-How-to-Chat-or-Call-a-Woman-to-Get-Her-Hooked-and-Fall-in-Love-Unlike-Those-Boring-Nice-Guys-by-Joe-Clef.pdf
    • http://loaminoo.linkpc.net/6093097091096095/Chat-Joe-Gunther-18-by