Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2514a3528622ed0…

MALICIOUS

PDF

20.5 KB Created: 2019-05-01 20:01:36 +01:00 Authoring application: mPDF 5.7
MD5: 9617ff9981d88fd40df32729473cb108 SHA-1: cf9adce4502da3a6c23c62f5dbb0ba0a6fe9305f SHA-256: e2514a3528622ed036e8e0d218760f51ecb3ba9cff8fdba52ffcd8d4453c3967
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file was identified as malicious due to a critical heuristic firing for a PDF SEO link farm. This indicates the document is designed to host a large number of external links, likely to distribute malicious content or for search engine optimization manipulation. While no scripts were extracted, the presence of numerous embedded URLs suggests a delivery mechanism for further compromise.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6091093092091/Cold-Case-by-Philip-Gourevitch.pdf
    • http://loaminoo.linkpc.net/6094096093098096/The-2007-Report-on-Standard-Mayonnaise-World-Market-Segmentation-by-City-by-Philip-M-Parker.pdf
    • http://loaminoo.linkpc.net/7090093094096099/The-Book-of-the-Standard-Nine---A-Complete-Guide-for-Owner-Drivers-and-Prospective-Purchasers-of-All-Standard-Nines-from-1932-1938-by-John-Speedwell.pdf
    • http://loaminoo.linkpc.net/5090095097099/The-Standard-Standard-1-by-John-Reinhard-Dizon.pdf
    • http://loaminoo.linkpc.net/7091098099099097/Standard-of-Excellence-Book-1-Comprehensive-Band-Method-Book-1-Trombone-Bass-Clef-Standard-of-Excellence-Series-by-Bruce-Pearson.pdf
    • http://loaminoo.linkpc.net/1097094098096099/Standard-Romance-Story-Fireman-Edition-Standard-Romance-Story-1-by-M-S-Willis.pdf
    • http://loaminoo.linkpc.net/5099094099095096/Operating-Systems-Concepts-and-Design-by-Milan-Milenkovic.pdf
    • http://loaminoo.linkpc.net/4093092094094/Operating-Instructions-A-Journal-of-My-Son-s-First-Year-by-Anne-Lamott.pdf
    • http://loaminoo.linkpc.net/8095099092092094/A-History-of-Railroad-Accidents-Safety-Precautions-and-Operating-Practices-by-Robert-B-Shaw.pdf
    • http://loaminoo.linkpc.net/5097093096098093/Green-Side-Up-Straight-Talk-on-Growing-amp-Operating-A-Profitable-Landscape-Business-by-Ed-Laflamme.pdf
    • http://loaminoo.linkpc.net/5090097095099094/Criminal-Procedure-in-Ghana-by-A-N-E-Amissah.pdf
    • http://loaminoo.linkpc.net/6099097094095097/Code-de-proc-dure-civile-by-Unknown.pdf
    • http://loaminoo.linkpc.net/2093091097097095/Experimental-Procedure-by-A-Maire-Dinsmore.pdf
    • http://loaminoo.linkpc.net/5097097097093095/Procedure-Penale-by-Claude-Garcin.pdf
    • http://loaminoo.linkpc.net/5094098090096098/Civil-Procedure-in-South-Africa-by-Roshana-Kelbrick.pdf
    • http://loaminoo.linkpc.net/1090093092094097097/My-Pectus-Journey-The-Nuss-Procedure-by-Paul-Shepherd.pdf
    • http://loaminoo.linkpc.net/1091094097095099092/Criminal-Procedure-in-Hong-Kong-by-Gary-N-Heilbronn.pdf
    • http://loaminoo.linkpc.net/8093094091095/Police-Procedure-amp-Investigation-A-Guide-for-Writers-by-Lee-Lofland.pdf
    • http://loaminoo.linkpc.net/6099091099094093/Database-Reliability-Engineering-Designing-and-Operating-Resilient-Database-Systems-by-Laine-Campbell.pdf
    • http://loaminoo.linkpc.net/6092099090096097/Practice-and-Procedure-in-Civil-Matters-in-the-Courts-of-Records-in-Anglophone-Cameroon-by-Michael-A-Yanou.pdf
    • http://loaminoo.linkpc.net/7091098099099097/Standard-of-Excellence-Book-1-Comprehensive-Band