Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6a64ba28dfc4fc8…

MALICIOUS

PDF

13.3 KB Created: 2019-05-05 13:09:34 +01:00 Authoring application: mPDF 5.7
MD5: 75e52c3744d16f60b39cc520ce810737 SHA-1: a02be6eaf7a39554e87535cd68d94a744959610c SHA-256: f6a64ba28dfc4fc87d41df54016494c5ad7ecc5b3c84d6a6cf331ab1d40d2c68
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents hosted on the 'loaminoo.linkpc.net' domain. While the extracted URLs are currently labeled as benign, the sheer volume and structure suggest a potential attempt to manipulate search engine results or to serve as a distribution point for malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4094096092098092/The-Small-Hand-and-Dolly-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/1090099093097099093/Dolly-on-Dolly-Interviews-and-Encounters-with-Dolly-Parton-by-Dolly-Parton.pdf
    • http://loaminoo.linkpc.net/1090099093099096091/Dolly-3-The-Dolly-Trilogy-3-by-Jubilee-Savage.pdf
    • http://loaminoo.linkpc.net/3093096093099091/The-Dolly-Dolly-Spy-by-Adam-Diment.pdf
    • http://loaminoo.linkpc.net/8095099096091098/Hunger-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/2093098095096099/The-Travelling-Bag-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/1091096094095092095/Black-Sheep-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/1097096093095097/The-Woman-In-Black-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/7093091099096/The-Small-Hand-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/6099091093097099/Femeia-n-negru-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/7096090099090091/The-Prime-of-Ms-Dolly-Greene-Dolly-Greene-1-by-E-V-Harte.pdf
    • http://loaminoo.linkpc.net/4098097091090093/The-Various-Haunts-of-Men-Simon-Serrailler-1-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/3096098091098098/The-Risk-of-Darkness-Simon-Serrailler-3-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/2096096092098093/The-Vows-of-Silence-Simon-Serailler-4-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/2096095099097095/The-Pure-in-Heart-Simon-Serrailler-2-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/1097099094091095/A-Question-of-Identity-Simon-Serrailler-7-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/1097096093092098/Howards-End-is-on-the-Landing-A-Year-of-Reading-from-Home-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/7093091093092096/Mrs-De-Winter-The-Sequel-To-Daphne-Du-Maurier-s-Rebecca-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/1099095098090098/Stuart-Little-at-the-Library-An-I-Can-Read-Picture-Book-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/4094095090097092/The-Penguin-Book-Of-Modern-Women-s-Short-Stories-by-Susan-Hill.pdf
    • http://loaminoo.linkpc.net/3096098091098098/The-Risk-of-Darkness-Simon-Serrailler-3-by