Malicious PDF — malware analysis report

Static analysis result for SHA-256 e13908aeb6a88310…

MALICIOUS

PDF

20.5 KB Created: 2019-05-03 05:42:32 +01:00 Authoring application: mPDF 5.7
MD5: 9582afb15bc4ad8858b165538d3a893d SHA-1: e7b6af0cce8917263cd15ab4ec0fda0ffe3e50d5 SHA-256: e13908aeb6a883100c67e7ed9a18ef59ca44f8fefc1d0aa2ca8418f8ae0c183f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various book titles hosted on the 'loaminoo.linkpc.net' domain. While the individual URLs are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation, traffic redirection, or as a distribution point for further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7098093095096093/The-Life-and-Letters-of-John-Muir-Volume-I-by-WILLIAM-FREDERIC-BALDE.pdf
    • http://loaminoo.linkpc.net/7098093095096092/The-Life-and-Letters-of-John-Muir-Volume-I---Primary-Source-Edition-by-WILLIAM-FREDERIC-BALDE.pdf
    • http://loaminoo.linkpc.net/6091098097094097/Life-of-Mahomet-by-Washington---Irving.pdf
    • http://loaminoo.linkpc.net/6091098097094093/The-Life-of-Mahomet-by-Washington-Irving.pdf
    • http://loaminoo.linkpc.net/3094090097091098/The-Wild-Muir-Twenty-Two-of-John-Muir-s-Greatest-Adventures-by-Lee-Stetson.pdf
    • http://loaminoo.linkpc.net/2099095090092094/The-Oxford-Book-of-Humorous-Prose-From-William-Caxton-to-P-G-Wodehouse-by-Frank-Muir.pdf
    • http://loaminoo.linkpc.net/2099099092097/A-Passion-for-Nature-The-Life-of-John-Muir-by-Donald-Worster.pdf
    • http://loaminoo.linkpc.net/6091098097094096/Mahomet-the-Illustrious-by-Godfrey-Higgins-Esq.pdf
    • http://loaminoo.linkpc.net/1093092099090094/William-Wilberforce-The-Life-of-the-Great-Anti-Slave-Trade-Campaigner-by-William-Hague.pdf
    • http://loaminoo.linkpc.net/7097099096097099/Charlie-Hebdo-Mahomet-Qui-Offense-Qui-by-Thierry-Verdier.pdf
    • http://loaminoo.linkpc.net/6091098097093097/An-Unofficial-History-of-Mahomet-Illinois-by-Mayhaven-Publishing.pdf
    • http://loaminoo.linkpc.net/1091094099091097094/The-Complete-Works-of-William-Shakespeare-comprising-his-plays-and-poems-also-the-history-of-his-life-his-will-and-an-introduction-to-each-play-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/5097097098098090/The-Complete-Works-of-William-Shakespeare-With-Historical-and-Analytical-Prefaces-Comments-Critical-and-Explanatory-Notes-Glossaries-a-Life-of-Sh-by-William-Shakespeare.pdf
    • http://loaminoo.linkpc.net/4097099091090090/Shakespeare-s-Other-Anne-A-Short-Account-Of-The-Life-And-Works-Of-Anne-Whateley-Or-Beck-A-Sister-Of-The-Order-Of-St-Clare-Who-Nearly-Married-William-Shakespeare-In-November-1582-A-D-by-William-J-Fraser-Hutcheson.pdf
    • http://loaminoo.linkpc.net/9096093093096098/In-the-Lap-of-Morpheus-by-R-Muir.pdf
    • http://loaminoo.linkpc.net/2097099097092098/Going-Back-for-Romeo-by-L-L-Muir.pdf
    • http://loaminoo.linkpc.net/3095092090096098/Breaking-Away-by-Tonya-Muir.pdf
    • http://loaminoo.linkpc.net/4097091093098095/Stickeen-by-John-Muir.pdf
    • http://loaminoo.linkpc.net/4099095099090091/What-A-Mess-Has-Tea-by-Frank-Muir.pdf
    • http://loaminoo.linkpc.net/1092096092092/All-But-the-Queen-of-Hearts-by-Rae-Muir.pdf
    • http://loaminoo.linkpc.net/7097099096097099/Charli