Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1072cd5b2207bca…

MALICIOUS

PDF

16.6 KB Created: 2019-04-30 05:29:45 +01:00 Authoring application: mPDF 5.7
MD5: 4aa511c341e51cbaecab6a678854e1c9 SHA-1: 3ec3eeea1c7b1f100bdf347a2ad0c0d848797c75 SHA-256: e1072cd5b2207bcad40273902a969952312b5094e023636608fbfa9d5ed44b44
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on loaminoo.linkpc.net. While the URLs themselves are labeled as confirmed benign, the sheer volume and structure suggest a link farm or distribution mechanism rather than legitimate document content. The attack pattern is likely to mislead users into clicking these links, potentially for SEO manipulation or to serve as a distribution point for further malicious activity.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4093094092091095/Where-the-Sun-Hides-Seasons-of-Betrayal-1-by-Bethany-Kris.pdf
    • http://loaminoo.linkpc.net/4095096094098099/Breathless-amp-Bloodstained-The-Chicago-War-4-by-Bethany-Kris.pdf
    • http://loaminoo.linkpc.net/4095096097095097/Lucian-Filthy-Marcellos-1-by-Bethany-Kris.pdf
    • http://loaminoo.linkpc.net/4095096096090098/Thin-Lies-Donati-Bloodlines-1-by-Bethany-Kris.pdf
    • http://loaminoo.linkpc.net/4098096097098091/Chicago-War-The-Complete-Series-The-Chicago-War-1-4-by-Bethany-Kris.pdf
    • http://loaminoo.linkpc.net/4095096098097093/Cross-Catherine-The-Companion-Cross-Catherine-4-by-Bethany-Kris.pdf
    • http://loaminoo.linkpc.net/8096093095092091/Winterm-rchen-in-Bethany-Bethany-3-by-Andr-Berlekamp.pdf
    • http://loaminoo.linkpc.net/2096092099091095/Betrayal-of-Justice-Zachary-Blake-Betrayal-2-by-Mark-M-Bello.pdf
    • http://loaminoo.linkpc.net/1091094092096093096/The-Four-Seasons-Sintram-and-His-Companions-Undine-The-Two-Captains-amp-Aslauga-s-Knight-The-Four-Seasons-1-4-by-Friedrich-Heinrich-Karl-de-la-Motte-Fouqu-.pdf
    • http://loaminoo.linkpc.net/1091096098090092091/Kris-Scholz-Photography-Landscapes-Portraits-Architecture-Flowers-by-Kris-Scholz.pdf
    • http://loaminoo.linkpc.net/6093090098091/Where-Treasure-Hides-by-Johnnie-Alexander.pdf
    • http://loaminoo.linkpc.net/3095090093090094/What-the-Light-Hides-by-Mette-Jakobsen.pdf
    • http://loaminoo.linkpc.net/3093097096098093/Kris-Longknife-s-Maid-goes-on-Strike-Kris-Longknife-15-5-by-Mike-Shepherd.pdf
    • http://loaminoo.linkpc.net/1094091096094091/Apex-Hides-the-Hurt-by-Colson-Whitehead.pdf
    • http://loaminoo.linkpc.net/4092093096097098/At-Least-My-Belly-Hides-My-Cankles-Mostly-True-Tales-of-An-Impending-Miracle-by-Paige-Kellerman.pdf
    • http://loaminoo.linkpc.net/4099090091096090/Kris-Jenner-and-All-Things-Kardashian-by-Kris-Jenner.pdf
    • http://loaminoo.linkpc.net/8091093095/Mem-by-Bethany-C-Morrow.pdf
    • http://loaminoo.linkpc.net/1091091097093/See-How-They-Run-by-Bethany-Campbell.pdf
    • http://loaminoo.linkpc.net/7095096091093093/Amy-Inspired-by-Bethany-Pierce.pdf
    • http://loaminoo.linkpc.net/9099099090098090/What-to-Do-about-the-Solomons-by-Bethany-Ball.pdf
    • http://loaminoo.linkpc.net/1091094092096093096/The-Four-Seasons-Sintram-and-His-Companions-Undine-The-Two-Captains-amp-Aslauga-s-Knight-The-Four-Seasons-1-4-by-Friedrich-He