Malicious PDF — malware analysis report

Static analysis result for SHA-256 f84d81edaa7a62f6…

MALICIOUS

PDF

17.2 KB Created: 2019-05-07 04:36:14 +01:00 Authoring application: mPDF 5.7
MD5: 81849b7e37e0ad83beadae2149377eb9 SHA-1: 91a48b424d5df1af230dddc60a772f568c4e7190 SHA-256: f84d81edaa7a62f68d0811999bc726d9118efbea4ef0d8ab6aa8b16afa73e99f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO manipulation or to host malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external PDF link farm, with the dominant host being loaminoo.linkpc.net. While the specific URLs extracted were labeled as benign, the overall structure suggests a malicious intent to redirect users to a large collection of documents, potentially for phishing or malware distribution.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3090096093092096/Uncanny-X-Men-2011-2012-6-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/2093091094093091/New-Mutants-11-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/3091096096095097/The-Wicked-The-Divine-10-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/3091093097095094/The-Wicked-The-Divine-6-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/3090095092099094/Avengers-vs-X-Men-Consequences-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/3090094093098096/Journey-into-Mystery-Fear-Itself-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/4093090093098093/The-Wicked-The-Divine-Vol-2-Fandemonium-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/3094090090095095/Darth-Vader-Omnibus-Vol-1-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/8091098097091092/Iron-Man-Volume-5-Rings-of-the-Mandarin-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/3090095093090091/Journey-into-Mystery-New-Mutants-Exiled-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/1091091094094096099/Uncanny-X-Men-1963-2011-453-by-Chris-Claremont.pdf
    • http://loaminoo.linkpc.net/1090096092096091098/Uncanny-X-Men-1963-2011-454-by-Chris-Claremont.pdf
    • http://loaminoo.linkpc.net/1091095096096099091/Uncanny-X-Men-1963-2011-459-by-Chris-Claremont.pdf
    • http://loaminoo.linkpc.net/9097092097091098/Uncanny-X-Men-1963-2011-456-by-Chris-Claremont.pdf
    • http://loaminoo.linkpc.net/6097097090096097/least-i-could-do-v9-Oct-2011---Sep-2012-by-Ryan-Sohmer.pdf
    • http://loaminoo.linkpc.net/8094099097096098/New-GRE-2011-2012-Premier-with-CD-ROM-by-Kaplan-Inc-.pdf
    • http://loaminoo.linkpc.net/1090097091093091090/Esel-2011-Donkeys-2011-nes-2011-by-Hans-Reinhard.pdf
    • http://loaminoo.linkpc.net/3093099097095092/Star-Wars-Doctor-Aphra-Vol-2-The-Enormous-Profit-Star-Wars-Doctor-Aphra-2-by-Kieron-Gillen.pdf
    • http://loaminoo.linkpc.net/4090098090095098/Advanced-Communication-And-Networking-International-Conference-Acn-2011-Brno-Czech-Republic-August-15-17-2011-Proceedings-by-Tai-Hoon-Kim.pdf
    • http://loaminoo.linkpc.net/5096098096093091/Autonomous-and-Intelligent-Systems-Third-International-Conference-AIS-2012-Aviero-Portugal-June-25-27-2012-Proceedings-by-Mohamed-Kamel.pdf
    • http://loaminoo.linkpc.net/