Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2a2102f2248793f…

MALICIOUS

PDF

16.7 KB Created: 2019-05-02 01:53:25 +01:00 Authoring application: mPDF 5.7
MD5: 849c6d8e2c752397281ff785237c9da0 SHA-1: 7f3e2672673ef2785417c8f8d19fb2b811fe02c9 SHA-256: e2a2102f2248793f21f1074ce999978d32c142f5d06a53e413915f9b68f8ff2e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents hosted on the 'loaminoo.linkpc.net' domain. While the individual linked PDFs are currently marked as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO poisoning or to distribute further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2094096097096098/Rose-s-Story-The-Girls-of-Lighthouse-Lane-2-by-Thomas-Kinkade.pdf
    • http://loaminoo.linkpc.net/4090090090095092/A-Christmas-Star-Cape-Light-9-by-Thomas-Kinkade.pdf
    • http://loaminoo.linkpc.net/5098094099098093/Snowfall-on-Lighthouse-Lane-Honeymoon-Harbor-2-by-JoAnn-Ross.pdf
    • http://loaminoo.linkpc.net/1095093096099092/Addy-Saves-the-Day-A-Summer-Story-American-Girls-Addy-5-by-Connie-Rose-Porter.pdf
    • http://loaminoo.linkpc.net/1095093096098093/Happy-Birthday-Addy-A-Springtime-Story-American-Girls-Addy-4-by-Connie-Rose-Porter.pdf
    • http://loaminoo.linkpc.net/4092095091095097/A-Wilder-Rose-Rose-Wilder-Lane-Laura-Ingalls-Wilder-and-Their-Little-Houses-by-Susan-Wittig-Albert.pdf
    • http://loaminoo.linkpc.net/3092096098094090/Big-Girls-Don-t-Cry-by-Gretchen-Lane.pdf
    • http://loaminoo.linkpc.net/9092094091094090/The-Making-of-Herbert-Hoover-by-Rose-Wilder-Lane.pdf
    • http://loaminoo.linkpc.net/1099099095093090/Most-Delicious-of-Privileges-by-Thomas-E-Lane.pdf
    • http://loaminoo.linkpc.net/1090096090099099091/The-Rediscovered-Writings-of-Rose-Wilder-Lane-Literary-Journalist-by-Amy-Mattson-Lauters.pdf
    • http://loaminoo.linkpc.net/5094095097099099/Ten-Little-Girls-Rebekka-Franck-9-by-Willow-Rose.pdf
    • http://loaminoo.linkpc.net/2092091090094096/Gossip-From-the-Girls-Room-A-Blogtastic-Novel-by-Rose-Cooper.pdf
    • http://loaminoo.linkpc.net/5090091092091094/The-Rose-Ransom-Girls-Wearing-Black-3-by-Spencer-Baum.pdf
    • http://loaminoo.linkpc.net/3092092098094091/Farriers-Lane-Charlotte-amp-Thomas-Pitt-13-by-Anne-Perry.pdf
    • http://loaminoo.linkpc.net/3096092097092092/Farrier-s-Lane-Charlotte-amp-Thomas-Pitt-13-by-Anne-Perry.pdf
    • http://loaminoo.linkpc.net/1091093096099091092/Dorothy-Thompson-and-Rose-Wilder-Lane-Forty-Years-of-Friendship-Letters-1921-1960-by-William-Holtz.pdf
    • http://loaminoo.linkpc.net/3095095099096098/Out-A-Cam-Thomas-Story-Cam-Thomas-1-by-Claire-Highton-Stevenson.pdf
    • http://loaminoo.linkpc.net/5097098099096090/The-Gamma-Girls-of-Chagrin-Falls-Lillie-Rose-and-Irisa-by-Janet-Kuivila.pdf
    • http://loaminoo.linkpc.net/5092093099099/Dream-Girls-Box-Set-by-Carrie-Thomas.pdf
    • http://loaminoo.linkpc.net/6096094092091098/A-Story-of-Gaia-by-Mika-Lane.pdf
    • http://loaminoo.linkpc.net/1090096090099