Malicious PDF — malware analysis report

Static analysis result for SHA-256 cbf692aa63168337…

MALICIOUS

PDF

22.4 KB Created: 2019-05-07 08:45:48 +01:00 Authoring application: mPDF 5.7
MD5: 703194ac99c905cff6b55f38261dcf02 SHA-1: cd1eb07772115d373a9c8b8b0e9a00158bb01fb0 SHA-256: cbf692aa63168337680a9e162dec8758c4b9f5293ece0a823566d3eb7f766cfe
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various book titles hosted on loaminoo.linkpc.net. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a link farm or traffic-driving scheme rather than legitimate content. The document body is heavily obfuscated, preventing a clear understanding of its direct intent beyond the link farm. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090092097092091091/Marvin-Redpost-Complete-Collection-8-books-by-Louis-Sachar.pdf
    • http://loaminoo.linkpc.net/1090094091098094099/Novels-by-Louis-Sachar-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/1090098098094095093/Albums-Produced-by-Leon-Ware-I-Want-You-the-Master-Anthology-Marvin-Gaye-the-Very-Best-of-Marvin-Gaye-Marvin-Gaye-s-Greatest-Hits-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/3092096091097091/Holes-by-Louis-Sachar.pdf
    • http://loaminoo.linkpc.net/8093099095098/The-Cardturner-by-Louis-Sachar.pdf
    • http://loaminoo.linkpc.net/4091095093099098/The-Beam-The-Complete-Second-Season-Collection-Books-7-12-by-Sean-Platt.pdf
    • http://loaminoo.linkpc.net/1091094090098092090/Wayside-School-Is-Falling-Down-by-Louis-Sachar.pdf
    • http://loaminoo.linkpc.net/1090094091098094093/Louis-Sachar-by-Wade-Anastasia-Jere.pdf
    • http://loaminoo.linkpc.net/1098091090092097/Sixth-Grade-Secrets-by-Louis-Sachar.pdf
    • http://loaminoo.linkpc.net/4091093098096096/The-Cardturner-A-Novel-about-a-King-a-Queen-and-a-Joker-by-Louis-Sachar.pdf
    • http://loaminoo.linkpc.net/8097090095092/Wayside-School-Gets-A-Little-Stranger-By-Louis-Sachar-A-Novel-Study-by-Ron-Leduc.pdf
    • http://loaminoo.linkpc.net/1090094091098095091/There-s-a-Boy-in-the-Girl-s-Bathroom-by-Louis-Sachar-Teacher-Guide-by-Anne-Troy.pdf
    • http://loaminoo.linkpc.net/7098096092091099/Audio-Cd-And-3-Board-Books-Complete-Collection-Of-32-Arabic-Rhymes-This-Is-The-Way-Fish-Swim-Tasseh-Tarantaseh-My-Turtle-s-Name-Is-Nahla-by-Taghreed-A-Najjar.pdf
    • http://loaminoo.linkpc.net/5092099099094094/The-Chronicles-of-Narnia-Complete-7-Book-Collection-All-7-Books-Plus-Bonus-Book-Boxen-by-C-S-Lewis.pdf
    • http://loaminoo.linkpc.net/7096091092091/Ride-the-River-Louis-Lamour-Collection-by-Louis-L-39-Amour.pdf
    • http://loaminoo.linkpc.net/1090095096094093095/You-Be-the-Jury-Courtroom-Collection-by-Marvin-Miller.pdf
    • http://loaminoo.linkpc.net/9099094092093094/The-Complete-Works-of-Marvin-K-Mooney-by-Christopher-Higgs.pdf
    • http://loaminoo.linkpc.net/1090092097091097090/Complete-and-Systematic-Concordance-of-Works-of-Shakespeare-by-Marvin-Spevack.pdf
    • http://loaminoo.linkpc.net/8095090091090091/Catalogue-of-a-Magnificent-Collection-of-Elegant-French-Furniture-and-Rare-Art-Objects-from-the-Period-of-Napoleon-Louis-XIV-XV-and-XVI-To-Be-Sold-by-Public-Auction-Under-the-Personal-Supervision-of-Mons-Jules-Ratzkowski-Art-Expert-of-Paris-and-Cairo-by-Louis-Deschenes.pdf
    • http://loaminoo.linkpc.net/6092097090091097/The-Nag-Hammadi-Scriptures-The-Revised-and-Updated-Translation-of-Sacred-Gnostic-Texts-Complete-in-One-Volume-by-Marvin-W-Meyer.pdf
    • http://loaminoo.linkpc.net