Malicious PDF — malware analysis report

Static analysis result for SHA-256 feed37588ecd365e…

MALICIOUS

PDF

16.4 KB Created: 2019-04-30 04:33:54 +01:00 Authoring application: mPDF 5.7
MD5: 5938abe5adf806bb94d8f8135112dbd6 SHA-1: c05cbae8d7ff1191857423e1a927e85c66edda10 SHA-256: feed37588ecd365eaa2cb76223a35d034bb363b589dae12f264ba61a0b44b589
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on loaminoo.linkpc.net. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a potential SEO manipulation scheme or a link farm designed to distribute malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2095095098090/The-Baby-and-the-Cowboy-SEAL-Cowboy-SEALs-2-by-Laura-Marie-Altom.pdf
    • http://loaminoo.linkpc.net/4093098095099094/A-SEAL-s-Secret-Baby-by-Laura-Marie-Altom.pdf
    • http://loaminoo.linkpc.net/4099099094097092/The-Cowboy-s-Surprise-Baby-Cowboy-Country-3-by-Deb-Kastner.pdf
    • http://loaminoo.linkpc.net/4091098091091094/Cowboy-SEAL-Christmas-Navy-SEAL-Cowboys-3-by-Nicole-Helm.pdf
    • http://loaminoo.linkpc.net/2093093099091094/You-Don-t-Have-to-Be-a-Star-Once-Upon-a-Cowboy-Montana-Fire-0-5-Cowboy-Fairytales-1-by-Susan-May-Warren.pdf
    • http://loaminoo.linkpc.net/3094098095095096/Cowboy-Famous-Cowboy-Justice-Association-4-by-Olivia-Jaymes.pdf
    • http://loaminoo.linkpc.net/3094097098095095/Cowboy-Truth-Cowboy-Justice-Association-3-by-Olivia-Jaymes.pdf
    • http://loaminoo.linkpc.net/8090096096095095/Forever-Kind-of-Cowboy-Cowboy-Dreamin-5-by-Sandy-Sullivan.pdf
    • http://loaminoo.linkpc.net/2090094094097096/Cowboy-Charming-Cowboy-Fairytales-2-by-Lacy-Williams.pdf
    • http://loaminoo.linkpc.net/3092091099095095/Tyler-s-Cowboy-Cowboy-Lovin-1-by-Amber-Kell.pdf
    • http://loaminoo.linkpc.net/1096094094094090/Cowboy-Baby-by-Sue-Heap.pdf
    • http://loaminoo.linkpc.net/5093098093096094/At-the-Cowboy-s-Mercy-Taming-the-Cowboy-1-by-Emma-Jay.pdf
    • http://loaminoo.linkpc.net/5093098094092096/Cowboy-Town-Down-Under-Cowboy-1-by-Kasey-Millstead.pdf
    • http://loaminoo.linkpc.net/2093093099091099/The-Cowboy-s-Baby-Bond-Montana-Cowboys-2-by-Linda-Ford.pdf
    • http://loaminoo.linkpc.net/3094095093093098/Faith-in-My-Cowboy-My-Cowboy-2-by-Brooke-May.pdf
    • http://loaminoo.linkpc.net/2095096094091/Cowboy-for-Hire-Forever-Texas-11-by-Marie-Ferrarella.pdf
    • http://loaminoo.linkpc.net/4094090098090094/Fighting-Love-for-the-Cowboy-A-Moose-Falls-Romance-Book-1-by-Anne-Marie-Meyer.pdf
    • http://loaminoo.linkpc.net/2092099099093093/The-Cowboy-and-the-Angel-The-Cowboy-and-the-Angel-1-by-Lietha-Wards.pdf
    • http://loaminoo.linkpc.net/1099099091094092/Calvin-s-Cowboy-Calvin-s-Cowboy-1-by-Drew-Hunt.pdf
    • http://loaminoo.linkpc.net/4092090097097098/Heart-of-Texas-Volume-3-Nell-s-Cowboy-amp-Lone-Star-Baby-Heart-of-Texas-5-6-by-Debbie-Macomber.pdf
    • http://loaminoo.linkpc.net/2090094094097096/Cowboy-Charming-Cowboy-Fairytales-2-by-Lacy-Williams