Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0921e713e2cbe45…

MALICIOUS

PDF

15.0 KB Created: 2019-04-29 23:35:53 +01:00 Authoring application: mPDF 5.7
MD5: 93fe46da90abf2332218fa83c2b6b5f6 SHA-1: 1ee747c6af4e2f63429c37c8e52a499238a40432 SHA-256: d0921e713e2cbe45ca16188eaf5db232f81a730ac1cf30dcace45a5f134685d3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF document contains a heuristic firing for a link farm, indicating a large number of external links embedded within the document body. The document body itself contains numerous URLs pointing to various book titles hosted on 'loaminoo.linkpc.net'. This suggests a social engineering attempt to direct users to potentially malicious or unwanted content disguised as legitimate links.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/5096091090096091/Le-Myst-re-de-Willoughby-by-Jane-Odiwe.pdf
    • http://loaminoo.linkpc.net/2098092091095093/Project-Darcy-by-Jane-Odiwe.pdf
    • http://loaminoo.linkpc.net/3098099095090095/Searching-for-Captain-Wentworth-by-Jane-Odiwe.pdf
    • http://loaminoo.linkpc.net/4094093099095/The-Book-of-Ti-ana-Myst-2-by-Rand-Miller.pdf
    • http://loaminoo.linkpc.net/2091095099096091/Warrior-of-the-Myst-Colonization-6-by-Scott-McElhaney.pdf
    • http://loaminoo.linkpc.net/4098092093092096/Prophecy-Isle-of-Myst-0-5-by-Stacie-Wilson.pdf
    • http://loaminoo.linkpc.net/5098092090094090/Audrey-Hepburn-by-Bob-Willoughby.pdf
    • http://loaminoo.linkpc.net/8095096090095/Who-Needs-Mr-Willoughby-by-Katie-Oliver.pdf
    • http://loaminoo.linkpc.net/2090098093090093/Just-Winging-It-Be-Wished-4-by-Kate-Willoughby.pdf
    • http://loaminoo.linkpc.net/1099090096090097/Out-of-the-Game-In-the-Zone-3-by-Kate-Willoughby.pdf
    • http://loaminoo.linkpc.net/2098092092091094/Under-the-Spotlight-In-the-Zone-4-by-Kate-Willoughby.pdf
    • http://loaminoo.linkpc.net/4095098090093094/The-Wolves-of-Willoughby-Chase-by-Joan-Aiken.pdf
    • http://loaminoo.linkpc.net/1099090097099094/Falling-for-Flynn-Hockey-on-Tap-1-by-Kate-Willoughby.pdf
    • http://loaminoo.linkpc.net/7094096090096092/School-for-Stars-Third-Term-at-L-Etoile-by-Holly-Willoughby.pdf
    • http://loaminoo.linkpc.net/1091099091091092094/The-Printing-of-the-First-Folio-of-Shakespeare-by-Edwin-Eliott-Willoughby.pdf
    • http://loaminoo.linkpc.net/7094096090095097/School-for-Stars-2-Second-Term-at-L-Etoile-by-Holly-Willoughby.pdf
    • http://loaminoo.linkpc.net/6093097090090096/Rubber-Fume---Ingredient-Emission-Relationships-by-Bryan-Willoughby.pdf
    • http://loaminoo.linkpc.net/4091090091090/The-Wolves-of-Willoughby-Chase-The-Wolves-Chronicles-1-by-Joan-Aiken.pdf
    • http://loaminoo.linkpc.net/5090092092097090/The-Wolves-of-Willoughby-Chase-The-Wolves-Chronicles-1-by-Joan-Aiken.pdf
    • http://loaminoo.linkpc.net/2090095096093092/Jane-and-the-Unpleasantness-at-Scargrave-Manor-Jane-Austen-Mysteries-1-by-Stephanie-Barron.pdf