Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4b41e8d2ed97f0e…

MALICIOUS

PDF

16.3 KB Created: 2019-05-01 17:03:28 +01:00 Authoring application: mPDF 5.7
MD5: 3fc43b926b9d045bc6f4c47066c92f17 SHA-1: f9de3b2c3324094ae97f9cc73b1f7e8196b1f40d SHA-256: e4b41e8d2ed97f0eab37db35704e3c4d92d33f92b9ad1d62f01e87e3e2e8c5cc
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on the 'loaminoo.linkpc.net' domain. While the individual linked PDFs are marked as benign, the sheer volume and structure suggest a link farm or SEO manipulation tactic, which can be used to distribute malicious content or improve the ranking of malicious sites. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097091099093091/Pups-to-the-Rescue-by-Nickelodeon-Publishing.pdf
    • http://loaminoo.linkpc.net/4097091098096092/Puppy-Birthday-to-You-by-Nickelodeon-Publishing.pdf
    • http://loaminoo.linkpc.net/3095090097096099/Dora-s-Bedtime-Adventures-by-Nickelodeon-Publishing.pdf
    • http://loaminoo.linkpc.net/4096092098099092/Chase-s-Space-Case-by-Nickelodeon-Publishing.pdf
    • http://loaminoo.linkpc.net/4090099094096090/Chase-is-on-the-Case-Paw-Patrol-by-Nickelodeon-Publishing.pdf
    • http://loaminoo.linkpc.net/6098091094095090/Mighty-Monster-Machines-Blaze-and-the-Monster-Machines-Little-Golden-Book-by-Nickelodeon-Publishing.pdf
    • http://loaminoo.linkpc.net/1091093091096090090/Pilot-Pups-by-Michelle-Meadows.pdf
    • http://loaminoo.linkpc.net/5094098092091096/-WeRateDogs-The-Most-Hilarious-and-Adorable-Pups-You-ve-Ever-Seen-by-Matt-Nelson.pdf
    • http://loaminoo.linkpc.net/2093090098090098/Let-Slip-the-Pups-of-War-Spot-and-Smudge---Book-Three-by-Robert-Udulutch.pdf
    • http://loaminoo.linkpc.net/1091090093096091099/Warrior-Pups-True-Stories-of-America-s-K9-Heroes-by-Jeff-Kamen.pdf
    • http://loaminoo.linkpc.net/2097092091096096/Slimed-An-Oral-History-of-Nickelodeon-s-Golden-Age-by-Mathew-Klickstein.pdf
    • http://loaminoo.linkpc.net/3091092090098099/Girls-to-the-Rescue-Book-4-Girls-to-the-Rescue-4-by-Bruce-Lansky.pdf
    • http://loaminoo.linkpc.net/3091091092096096/Girls-to-the-Rescue-Book-5-Girls-to-the-Rescue-5-by-Bruce-Lansky.pdf
    • http://loaminoo.linkpc.net/3091096090099090/Mexican-Mutts-Tequila-Pups-amp-Chili-Dogs-True-Stories-of-the-Dogs-of-Mexico-by-David-Gordon-Burke.pdf
    • http://loaminoo.linkpc.net/1091092091098093093/Rescue-the-Captors-Rescue-the-Captors-1-by-Russell-M-Stendal.pdf
    • http://loaminoo.linkpc.net/3092091097098090/Publish-on-Amazon-Kindle-with-Kindle-Direct-Publishing-by-Kindle-Direct-Publishing.pdf
    • http://loaminoo.linkpc.net/7091095098099096/Marseille-by-Euprintpress-Publishing.pdf
    • http://loaminoo.linkpc.net/1091092098097098094/Cheshire-Maxi-by-A-A-Publishing.pdf
    • http://loaminoo.linkpc.net/8097095092091092/Heilpflanzen-by-zentrum-publishing.pdf
    • http://loaminoo.linkpc.net/1091097093095098093/The-Panama-Canal-by-Cobblestone-Publishing.pdf
    • http://loaminoo.linkpc.net/5094098092091096/-WeRateDogs-The-Most-Hilarious-and-Adorable-Pups-You-ve-Ever-Seen-by-Matt-Nelson.pd