Malicious PDF — malware analysis report

Static analysis result for SHA-256 f198439b7f8681d0…

MALICIOUS

PDF

22.1 KB Created: 2019-04-30 05:13:46 +01:00 Authoring application: mPDF 5.7
MD5: 3a4eb4d7c6478a67210d8ac4020d5b46 SHA-1: 9ca730524e5904bc22015f4408d8664d6f3ad3e2 SHA-256: f198439b7f8681d0520894454b1eab912135ed1ba9e4e332fe5e23c88957bf76
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a link farm pointing to numerous external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This heuristic firing suggests a tactic to artificially inflate search engine rankings or distribute content through a large number of seemingly unrelated documents. While the linked PDFs themselves are marked as benign, the sheer volume and the use of a dynamic DNS hostname for hosting indicate a suspicious distribution method. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6091093098099098/Yoshoku-and-Chuka-The-Japanized-Western-and-Chinese-Dishes-by-Hikari-Dept-.pdf
    • http://loaminoo.linkpc.net/6091093097092095/Sushi-Its-Unknown-Varieties-and-History-by-Hikari-Dept-.pdf
    • http://loaminoo.linkpc.net/6091093096090095/Hikari-No-Densetsu-Tome-1-Legend-Of-Hikari-by-Izumi-As-.pdf
    • http://loaminoo.linkpc.net/4095094092094091/Lost-in-transliteration-The-tolerance-of-unintelligibility-in-Chinese-bibliographic-records-in-Western-libraries-by-Jyh-Ming-Yang.pdf
    • http://loaminoo.linkpc.net/8094094098099098/The-New-Astrology-A-Unique-Synthesis-Of-The-World-s-Two-Great-Astrological-Systems-The-Chinese-amp-Western-by-Suzanne-White.pdf
    • http://loaminoo.linkpc.net/2092092091097099/Creation-of-the-Gods-Library-of-Chinese-Classics-Chinese-English-4-Volumes-by-Xu-Zhonglin.pdf
    • http://loaminoo.linkpc.net/4096092099097094/The-Water-Dragon-A-Chinese-Legend---English-and-Chinese-bilingual-text-by-Li-Jian.pdf
    • http://loaminoo.linkpc.net/4099095092098096/Chinese-Gods-An-Introduction-to-Chinese-Folk-Religion-by-Jonathan-Chamberlain.pdf
    • http://loaminoo.linkpc.net/1099096097091091/The-Book-of-Chinese-Beliefs-A-Journey-Into-the-Chinese-Inner-World-by-Frena-Bloomfield.pdf
    • http://loaminoo.linkpc.net/3099099098092095/Kojo-the-Sea-Dragon-Gets-Lost-by-David-Chuka.pdf
    • http://loaminoo.linkpc.net/8098099093095098/The-Chinese-Mind-Understanding-Traditional-Chinese-Beliefs-and-Their-Influence-on-Contemporary-Culture-by-Boy-Lafayette-de-Mente.pdf
    • http://loaminoo.linkpc.net/5095091096094/Dept-of-Speculation-by-Jenny-Offill.pdf
    • http://loaminoo.linkpc.net/9094098092095093/Capturing-Chinese-Stories-Prose-and-Poems-by-Revolutionary-Chinese-Authors-Including-Lu-Xun-Hu-Shi-Zhu-Ziqing-Zhou-Zuoren-and-Lin-Yutang-by-Lu-Xun.pdf
    • http://loaminoo.linkpc.net/3099099098095095/Billy-and-the-Monster-Who-Ate-All-the-Easter-Eggs-by-David-Chuka.pdf
    • http://loaminoo.linkpc.net/4091096099098099/Billy-and-Monster-s-Golden-Christmas-by-David-Chuka.pdf
    • http://loaminoo.linkpc.net/9094098092090091/Chinese-Short-Stories-by-Revolutionary-Authors---Read-Chinese-Literature-with-Detailed-Footnotes-Pinyin-Summaries-and-Audio-by-Kevin-John-Nadolny.pdf
    • http://loaminoo.linkpc.net/6097093092092090/The-Marshal-and-the-Vigilance-Committee-A-Frontier-Boomtown-Western-Adventure-An-Animas-Forks-Western-Book-2-by-Robert-R-Peecher-Jr-.pdf
    • http://loaminoo.linkpc.net/3095097092094093/Western-The-Series-Western-Romance-1-by-Juliet-Sassy.pdf
    • http://loaminoo.linkpc.net/1098099090091098/Body-Heat-Dept-6-Hired-Guns-2-by-Brenda-Novak.pdf
    • http://loaminoo.linkpc.net/7099098098092096/Republic-of-Mozambique-by-International-Monetary-Fund-Afri-Dept.pdf
    • http://loaminoo.linkpc.net/4096092099097094/The-Water-Dragon-A