Malicious PDF — malware analysis report

Static analysis result for SHA-256 cfc38c81bea7b130…

MALICIOUS

PDF

24.8 KB Created: 2019-04-30 05:22:10 +01:00 Authoring application: mPDF 5.7
MD5: 8e776bca5f170d6927230c406617c5b8 SHA-1: 0fa598e206ee967f7465524016cf0bed0f3d3d61 SHA-256: cfc38c81bea7b13071df8b4bcdce973b221d147b6acced562e311b8cd13f1a7f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on the loaminoo.linkpc.net domain. While the document body is unreadable, the presence of a link farm suggests a potential SEO poisoning or traffic generation scheme, possibly leading to malicious content or phishing pages. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5099096093093096/Cinderella-and-the-Colonel-Timeless-Fairy-Tales-3-by-K-M-Shea.pdf
    • http://loaminoo.linkpc.net/1099098097097091/Cinderella-and-the-Colonel-Timeless-Fairy-Tales-3-by-K-M-Shea.pdf
    • http://loaminoo.linkpc.net/1099095092099097/Puss-in-Boots-Timeless-Fairy-Tales-6-by-K-M-Shea.pdf
    • http://loaminoo.linkpc.net/1090090093093094092/Erotic-Sex-Box-Set-Alice-in-Wonderland-Wizard-of-Oz-Frankenstein-Gulliver-3-Musketeers-50-Shades-of-Grey-s-Anatomy-Fairy-Tales-Sleeping-Beauty-Cinderella-Snow-White-Rapunzel-Goldilocks-Hansel-amp-Gretel-3-Pigs-Rumpelstilzchen-by-Rita-Freely.pdf
    • http://loaminoo.linkpc.net/4091094097098094/Americana-Fairy-Tale-Fairy-Tales-of-the-Open-Road-1-by-Lex-Chase.pdf
    • http://loaminoo.linkpc.net/3096092090090096/Americana-Fairy-Tale-Fairy-Tales-of-the-Open-Road-1-by-Lex-Chase.pdf
    • http://loaminoo.linkpc.net/7095094099090090/Ever-After-High-Once-Upon-a-Twist-Cerise-and-the-Beast-Fairy-Tale-Retelling-2-by-Lisa-Shea.pdf
    • http://loaminoo.linkpc.net/5094098090096093/Disney---Fathers-Aladar-Alan-Bradley-Amphytryon-and-Alcmene-Archimedes-Q-Porter-Auguste-Gusteau-Bayard-Big-Bad-Wolf-Blackbeard-Bob-Parr-Bootstrap-Bill-Turner-Bud-Robinson-Casey-Cassim-Chief-Powhatan-Chilkoot-Cinderella-s-Father-Colonel-H-by-Source-Wikia.pdf
    • http://loaminoo.linkpc.net/4097096094092098/Grimms-Fairy-Tales-Volume-2-Sleeping-Beauty-and-Other-Tales-by-Jacob-Grimm.pdf
    • http://loaminoo.linkpc.net/4094094098094094/Twisted-Tales-Six-Fairy-Tales-Turned-Inside-Out-by-Richard-Tulloch.pdf
    • http://loaminoo.linkpc.net/9091095099098/Her-Stories-African-American-Folktales-Fairy-Tales-and-True-Tales-by-Virginia-Hamilton.pdf
    • http://loaminoo.linkpc.net/4096096091097096/Mythology-Timeless-Tales-of-Gods-and-Heroes-by-Edith-Hamilton.pdf
    • http://loaminoo.linkpc.net/7096094098093091/The-Fairy-Family-A-Series-of-Ballads-amp-Metrical-Tales-Illustrating-the-Fairy-Mythology-of-Europe-By-A-MacLaren-by-A-MacLaren-a-Series-of-Ballads-amp-Metrical-Tales-Illustrating-the-Fairy-Mythology-of-Europe-By-A-MacLaren-by-A-MacLaren-by-Archibald-MacLaren.pdf
    • http://loaminoo.linkpc.net/2096092090097091/Grimm-s-Fairy-Tales-Children-s-and-Household-Tales-by-Jacob-Grimm.pdf
    • http://loaminoo.linkpc.net/1092099093097099/Cinderella-Steals-Home-Cinderella-3-by-Carly-Syms.pdf
    • http://loaminoo.linkpc.net/1099098092092093/The-Cinderella-Makeover-Suddenly-Cinderella-2-by-Hope-C-Tarr.pdf
    • http://loaminoo.linkpc.net/3091093097093094/Timeless-Timeless-1-by-Alexandra-Monir.pdf
    • http://loaminoo.linkpc.net/3099091094098091/Timeless-Timeless-1-by-Alexandra-Monir.pdf
    • http://loaminoo.linkpc.net/3097092096098/Timeless-Timeless-1-by-Alexandra-Monir.pdf
    • http://loaminoo.linkpc.net/6099090090097/Cinderella-in-Skates-Cinderella-2-by-Carly-Syms.pdf