Malicious PDF — malware analysis report

Static analysis result for SHA-256 2ce5d6ce8efb0ee2…

MALICIOUS

PDF

14.3 KB Created: 2019-05-01 17:07:24 +01:00 Authoring application: mPDF 5.7
MD5: 452eb84a30c168f9f1bf9da1fd3de5b3 SHA-1: 627897ed29a6720c3dc3974f38cd1c79a7ffaad1 SHA-256: 2ce5d6ce8efb0ee28531bc0965f2d88865f4b9ae6d2d47b556d72c819729c47b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, all pointing to the same domain 'loaminoo.linkpc.net' and formatted as book titles. This suggests a link farm or SEO poisoning technique designed to drive traffic to potentially malicious content. No scripts were extracted, and the document body primarily consists of these URLs. The primary attack pattern is the distribution of these links.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090092093098090094/Johnny-Appleseed-by-Gertrude-Norman.pdf
    • http://loaminoo.linkpc.net/1090092093095095095/Johnny-Appleseed-by-Jane-Kurtz.pdf
    • http://loaminoo.linkpc.net/1090092093097092099/Johnny-Appleseed-by-Christin-Ditchfield.pdf
    • http://loaminoo.linkpc.net/1090090098098094092/Who-Was-Johnny-Appleseed-by-Joan-Holub.pdf
    • http://loaminoo.linkpc.net/1090092093097099095/Johnny-Appleseed-by-Bill-Balcziak.pdf
    • http://loaminoo.linkpc.net/1090092093097091099/Johnny-Appleseed-by-Rosemary-Ben-t.pdf
    • http://loaminoo.linkpc.net/4096099090092/Better-Known-As-Johnny-Appleseed-by-Mabel-Leigh-Hunt.pdf
    • http://loaminoo.linkpc.net/1090092093097093091/Johnny-Appleseed-Man-amp-Myth-by-Robert-M-Price.pdf
    • http://loaminoo.linkpc.net/1090092093097092098/The-Legend-of-Johnny-Appleseed-by-Martin-Powell.pdf
    • http://loaminoo.linkpc.net/1090092093097099090/Johnny-Appleseed-Goes-A-Planting-by-Patsy-Jensen.pdf
    • http://loaminoo.linkpc.net/1090092093095095096/Johnny-Appleseed-The-Story-of-a-Legend-by-Will-Moses.pdf
    • http://loaminoo.linkpc.net/1090092093097093090/The-True-Tale-of-Johnny-Appleseed-by-Margaret-Hodges.pdf
    • http://loaminoo.linkpc.net/2095090098094097/Johnny-Appleseed-The-Man-the-Myth-the-American-Story-by-Howard-Means.pdf
    • http://loaminoo.linkpc.net/3096092094095092/Walt-Disney-Presents-The-Story-of-Johnny-Appleseed-by-Ted-Parmalee.pdf
    • http://loaminoo.linkpc.net/8092092095093/Appleseed-The-Scales-of-Prometheus-Appleseed-3-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/1090092093098090095/Appleseed-Vol-1-and-2-Appleseed-by-Masamune-Shirow.pdf
    • http://loaminoo.linkpc.net/7092094091092092/Dickie-Brennan-s-Palace-Cafe-The-Flavor-of-New-Orleans-by-Dick-Brennan.pdf
    • http://loaminoo.linkpc.net/2095090097095096/Johnny-s-Girl-Johnny-Be-Good-2-5-by-Paige-Toon.pdf
    • http://loaminoo.linkpc.net/2093094099099091/Thin-Places-A-Memoir-by-Mary-E-DeMuth.pdf
    • http://loaminoo.linkpc.net/8091099098091097/Johnny-Wander-Vol-3-Ballad-of-Laundry-Cat-Johnny-Wander-3-by-Ananth-Panagariya.pdf