Malicious PDF — malware analysis report

Static analysis result for SHA-256 252f14014e560a9b…

MALICIOUS

PDF

18.3 KB Created: 2019-04-30 18:38:21 +01:00 Authoring application: mPDF 5.7
MD5: 624ce40185e01ee0b8028d24c6cf3c64 SHA-1: 7aebdbea7e45074065348539e58d4f804ad1c17b SHA-256: 252f14014e560a9b0305d2655cc449b70f3ad117758d40eb6e677a721fd7ba9c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents hosted on the `loaminoo.linkpc.net` domain. This suggests a link farm or a method to distribute potentially malicious content indirectly. While the specific intent beyond linking is unclear due to the lack of executable scripts, the heuristic 'PDF_SEO_LINK_FARM' indicates a malicious pattern of generating SEO-like links to obscure the true purpose. The embedded URLs are the primary indicators of compromise.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092098098094091/Spirits-of-the-Plains-Book-one-of-the-Spirits-Saga-by-Daniel-Glen-Matuzas.pdf
    • http://loaminoo.linkpc.net/1090098091093093098/Die-Regenbogenfahne---Entstehung-und-Bedeutung-und-wissenswertes-ber-den-CSD-LBGTIQ-Symbole-und-dem-Two-Spirits-by-Sundance---Two-Spirits.pdf
    • http://loaminoo.linkpc.net/4097099090093095/Guardian-Spirits-Spirits-3-by-Jordan-L-Hawk.pdf
    • http://loaminoo.linkpc.net/9091090092093095/Dangerous-Spirits-Spirits-2-by-Jordan-L-Hawk.pdf
    • http://loaminoo.linkpc.net/1095095095093090/The-Sword-of-the-Spirits-Trilogy-The-Sword-of-the-Spirits-1-3-by-John-Christopher.pdf
    • http://loaminoo.linkpc.net/1094096095097094/Restless-Spirits-Restless-Spirits-1-by-Jean-Marie-Bauhaus.pdf
    • http://loaminoo.linkpc.net/4098095097091099/Love-Spirits-What-Happens-in-Venice-Book-One-by-Diana-Cachey.pdf
    • http://loaminoo.linkpc.net/1090099091099099090/Spirits-of-Falajen-Sethi-s-Song-Book-1-by-Ginger-Salazar.pdf
    • http://loaminoo.linkpc.net/3099094099096093/The-Legend-of-Korra-The-Art-of-the-Animated-Series-Book-Two-Spirits-by-Bryan-Konietzko.pdf
    • http://loaminoo.linkpc.net/1091092092090091098/The-Essential-Bar-Book-An-A-to-Z-Guide-to-Spirits-Cocktails-and-Wine-with-115-Recipes-for-the-World-s-Great-Drinks-by-Jennifer-Fiedler.pdf
    • http://loaminoo.linkpc.net/4095097095097097/School-For-Spirits-A-Dead-Girl-and-a-Samurai-Spirit-School-Book-1-by-Aron-Lewes.pdf
    • http://loaminoo.linkpc.net/4099099098096092/Human-All-Too-Human-A-Book-for-Free-Spirits-by-Friedrich-Nietzsche.pdf
    • http://loaminoo.linkpc.net/4096091092093096/The-Lost-Soul-Companion-A-Book-of-Comfort-and-Constructive-Advice-for-Black-Sheep-Square-Pegs-Struggling-Artists-and-Other-Free-Spirits-by-Susan-M-Brackney.pdf
    • http://loaminoo.linkpc.net/4097090095091090/Spirits-Abroad-by-Zen-Cho.pdf
    • http://loaminoo.linkpc.net/9091090094095095/Parallel-Spirits-by-T-S-Welti.pdf
    • http://loaminoo.linkpc.net/4097098094093091/Conversations-with-Spirits-by-E-O-Higgins.pdf
    • http://loaminoo.linkpc.net/1091094093094095/Spirits-of-Place-by-Jim-Perrin.pdf
    • http://loaminoo.linkpc.net/2099098090098093/Mean-Spirits-The-Mediator-3-by-Meg-Cabot.pdf
    • http://loaminoo.linkpc.net/3094092094097094/The-House-of-the-Spirits-by-Isabel-Allende.pdf
    • http://loaminoo.linkpc.net/7090098097098098/The-Trail-of-Many-Spirits-by-Serle-Chapman.pdf
    • http://loaminoo.linkpc.net/1090099091099099090/Spirits-of-Falaje