Malicious PDF — malware analysis report

Static analysis result for SHA-256 2bc71c716393deba…

MALICIOUS

PDF

17.6 KB Created: 2019-04-30 02:44:23 +01:00 Authoring application: mPDF 5.7
MD5: 5143275e570e3e677c3f859688f1769d SHA-1: 63d1ff312a6aea16584e8c0b2eeb7ded7f4977b7 SHA-256: 2bc71c716393debabca81c97a6dd6fae0b44eaae61324ee5b75fb03cabe6d21b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to a single domain, loaminoo.linkpc.net, which is indicative of a link farm. While the URLs themselves appear to point to book titles, the sheer volume and the domain's nature suggest a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malware. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2096095093097090/Family-Honor-Sunny-Randall-1-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/3099095090096094/Love-and-Honor-by-Randall-Wallace.pdf
    • http://loaminoo.linkpc.net/4092091094091095/Living-on-the-Sunny-Side-A-Memoir-by-Sunny-Deuber.pdf
    • http://loaminoo.linkpc.net/2092096092091091/Parker-s-Wine-Buyer-s-Guide-The-Complete-Easy-To-Use-Reference-on-Recent-Vintages-Prices-and-Ratings-for-More-Than-8-000-Wines-from-All-the-Major-Wine-Regions-by-Robert-M-Parker-Jr-.pdf
    • http://loaminoo.linkpc.net/1090091094096095095/History-of-Corporate-Governance-Around-the-World-A-Family-Business-Groups-to-Professional-Managers-by-Randall-K-Morck.pdf
    • http://loaminoo.linkpc.net/4097099099099/Reconciliation-Road-A-Family-Odyssey-of-War-and-Honor-by-John-Douglas-Marshall.pdf
    • http://loaminoo.linkpc.net/1091095095094099090/Blood-and-Honor-Inside-the-Scarfo-Mob--The-Mafia-s-Most-Violent-Family-by-George-Anastasia.pdf
    • http://loaminoo.linkpc.net/2098099097097098/Kiss-of-Fire-St-James-Family-Book-2-by-Lavender-Parker.pdf
    • http://loaminoo.linkpc.net/7093091093094092/Murder-of-Honor-A-by-Robert-Andrews.pdf
    • http://loaminoo.linkpc.net/5092091097099091/Frontier-Blood-The-Saga-of-the-Parker-Family-by-Jo-Ella-Powell-Exley.pdf
    • http://loaminoo.linkpc.net/3096091099098092/Playmates-Spenser-16-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/1090094099090092092/Miese-Gesch-fte-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/3095097090095091/Perchance-to-Dream-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/9097091095090097/A-Year-at-the-Races-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/3099091093091090/Playmates-Spenser-16-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/4091091090096095/Potshot-Spenser-28-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/2095096094099094/Mommy-Diagnostics-The-Naturally-Healthy-Family-s-Guide-to-Herbs-and-Whole-Foods-for-Health-by-Shonda-Parker.pdf
    • http://loaminoo.linkpc.net/4093096092098/The-Widening-Gyre-Spenser-10-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/4099091098094097/The-Judas-Goat-Spenser-5-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/2093093092094096/Early-Autumn-Spenser-7-by-Robert-B-Parker.pdf
    • http://loaminoo.linkpc.net/4097099099099/Reconciliation-Road-A-Fami