Malicious PDF — malware analysis report

Static analysis result for SHA-256 d350b1e4b467e069…

MALICIOUS

PDF

16.7 KB Created: 2019-04-30 05:32:33 +01:00 Authoring application: mPDF 5.7
MD5: 423e9d83440e11fb7d5aa1b87e35df30 SHA-1: 74afc135b846adb7f149f3c69d29bc5d85bcf761 SHA-256: d350b1e4b467e069c310c1a8497a7a5ca62c60c45759e3d8e35400d3d6ccc7fa
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, identified as a 'PDF_SEO_LINK_FARM' heuristic. These links point to various PDF files hosted on 'loaminoo.linkpc.net'. While the individual links are currently marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/3099094097092099/The-End-of-Tomorrow-The-Single-Lady-Spy-3-by-Tara-Brown.pdf
    • http://loaminoo.linkpc.net/1090098098098094099/Room-For-A-Single-Lady-by-Clare-Boylan.pdf
    • http://loaminoo.linkpc.net/4096098090097095/White-Girl-Problems-by-Tara-Brown.pdf
    • http://loaminoo.linkpc.net/4096095099095094/Fling-Club-Serendipity-1-by-Tara-Brown.pdf
    • http://loaminoo.linkpc.net/9098095098094090/Lady-Evelyn-s-Highland-Protector-by-Tara-Kingston.pdf
    • http://loaminoo.linkpc.net/5094097096095091/Enter-Helen-The-Invention-of-Helen-Gurley-Brown-and-the-Rise-of-the-Modern-Single-Woman-by-Brooke-Hauser.pdf
    • http://loaminoo.linkpc.net/9095099093099/Single-s-Guide-A-Single-Therapy-Guidebook-by-Hazel-Cartwright.pdf
    • http://loaminoo.linkpc.net/1098091092099090/The-Lady-in-the-Attic-Annie-s-Attic-Mysteries-1-by-Tara-Randel.pdf
    • http://loaminoo.linkpc.net/1096095094094092/Single-Handed-Single-Girls-1-by-Veronica-Blade.pdf
    • http://loaminoo.linkpc.net/4094093091096095/Single-Volume-2-Single-2-by-Lyra-Parish.pdf
    • http://loaminoo.linkpc.net/4093096093092093/Tomorrow-When-the-War-Began-The-Tomorrow-Series-1-by-John-Marsden.pdf
    • http://loaminoo.linkpc.net/1095095092093091/Yesterday-s-Tomorrow-Tomorrow-s-War-Book-1-by-G-W-Pomichter.pdf
    • http://loaminoo.linkpc.net/3093090092096/Tomorrow-When-the-War-Began-Tomorrow-1-by-John-Marsden.pdf
    • http://loaminoo.linkpc.net/3099098097094093/Redeemers-Redeemers-3-by-Tara-Brown.pdf
    • http://loaminoo.linkpc.net/4095090099090094/Born-Born-1-by-Tara-Brown.pdf
    • http://loaminoo.linkpc.net/1096093091099094/Tomorrow-and-Tomorrow-by-Charles-Sheffield.pdf
    • http://loaminoo.linkpc.net/7090096096092096/Alice-n-ara-Minunilor-Alice-n-ara-din-Oglind-by-Lewis-Carroll.pdf
    • http://loaminoo.linkpc.net/8099098098099095/THE-21-TARA-S-AND-MERIDIAN-TAPPING-How-To-Use-Meridian-Tapping-To-Awaken-The-Power-Of-The-Goddess-Tara-And-Her-21-Emanations-Tapping-Miracles-Series-Book-3-by-Doron-Alon.pdf
    • http://loaminoo.linkpc.net/4095095093097097/Lady-Merry-s-Dashing-Champion-Lady-Trilogy-3-by-Jeane-Westin.pdf
    • http://loaminoo.linkpc.net/3092090095093097/Lady-Slings-the-Booze-Lady-Sally-s-2-Callahan-s-5-by-Spider-Robinson.pdf