Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb9af884f0dd397b…

MALICIOUS

PDF

15.6 KB Created: 2019-05-02 17:23:45 +01:00 Authoring application: mPDF 5.7
MD5: 757e7359c2a7003057f806e961729f5b SHA-1: 37ba10dcf84cce39e5797149201a7be4942f5434 SHA-256: cb9af884f0dd397b00067107af436c419a62dc0cc82511f4fe48acae32a02b5e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on loaminoo.linkpc.net. While the URLs themselves are marked as confirmed benign, the sheer volume and pattern suggest a potential SEO manipulation or a link farm intended to distribute malicious content or redirect users to phishing sites. No scripts were extracted, limiting further analysis of direct payload execution.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099098093090098/Dragon-in-the-System-Geek-Love-1-by-Cindy-Spencer-Pape.pdf
    • http://loaminoo.linkpc.net/2095094095095098/Georgie-and-the-Dragon-by-Cindy-Spencer-Pape.pdf
    • http://loaminoo.linkpc.net/3092096095096098/Crazy-For-The-Cowboy-Love-at-the-Crazy-H-2-by-Cindy-Spencer-Pape.pdf
    • http://loaminoo.linkpc.net/8097097090099094/Moonlight-amp-Mechanicals-Gaslight-Chronicles-4-by-Cindy-Spencer-Pape.pdf
    • http://loaminoo.linkpc.net/1098099094096090/Steam-amp-Sorcery-Gaslight-Chronicles-1-by-Cindy-Spencer-Pape.pdf
    • http://loaminoo.linkpc.net/3092099091094093/Ashes-amp-Alchemy-Gaslight-Chronicles-6-by-Cindy-Spencer-Pape.pdf
    • http://loaminoo.linkpc.net/4098090095090092/Girl-Geek-Gaming-the-System-0-5-by-Brenna-Aubrey.pdf
    • http://loaminoo.linkpc.net/1099096091098096/A-Chance-To-Love-You-AMBW-Sexy-Geek-Series-Book-2-by-Love-Journey.pdf
    • http://loaminoo.linkpc.net/2093092092091099/The-Geek-Girl-and-the-Scandalous-Earl-Geek-Girls-1-by-Gina-Lamm.pdf
    • http://loaminoo.linkpc.net/1096092091098093/Forever-Geek-Geek-Girl-6-by-Holly-Smale.pdf
    • http://loaminoo.linkpc.net/1098090094099093/OMG-I-m-in-Love-with-a-Geek-Hattie-Moore-2-by-Rae-Earl.pdf
    • http://loaminoo.linkpc.net/4095091096092098/Band-Geek-Love-by-Josie-Bloss.pdf
    • http://loaminoo.linkpc.net/3094097097/The-Geek-s-Guide-to-Unrequited-Love-by-Sarvenaz-Tash.pdf
    • http://loaminoo.linkpc.net/4093091095095091/Beauty-and-the-Geek-Gone-Geek-1-by-Sidney-Bristol.pdf
    • http://loaminoo.linkpc.net/2094096095091090/Geek-God-Forever-Geek-1-by-Victoria-Barbour.pdf
    • http://loaminoo.linkpc.net/3090092094096097/Violca-s-Dragon-The-Dragon-Ruby-1-by-Leilani-Love.pdf
    • http://loaminoo.linkpc.net/2095094095098093/My-Little-Geek-My-Little-Geek-1-by-Andrew-Spear.pdf
    • http://loaminoo.linkpc.net/3097094092096097/G-A-Aiken-Dragon-Bundle-The-Dragon-Who-Loved-Me-What-a-Dragon-Should-Know-Last-Dragon-Standing-amp-How-to-Drive-a-Dragon-Crazy-The-Dragon-Kin-3-6-by-G-A-Aiken.pdf
    • http://loaminoo.linkpc.net/1095093094094/Endless-Love-by-Scott-Spencer.pdf
    • http://loaminoo.linkpc.net/1097092092093090/Endless-Love-by-Scott-Spencer.pdf