Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d4ed99619e8eb70…

MALICIOUS

PDF

20.6 KB Created: 2019-04-30 18:54:22 +01:00 Authoring application: mPDF 5.7
MD5: 95829232e6c8e05b518edfc2ffa0a2ee SHA-1: cec79564c9d1c5ce21c02eda4871b2e9a213de09 SHA-256: 2d4ed99619e8eb7060370c6ec8b56d6cd83c0f445d1dd45a830b9a243d5f1fa8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links all point to the same domain, loaminoo.linkpc.net, with varied book titles in the path. This suggests a link farm or SEO manipulation tactic. While the URLs themselves are marked as benign, the sheer volume and structure indicate a malicious intent to drive traffic or potentially distribute further payloads. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/2098099093097097/On-a-Snowy-Night-The-Christmas-Basket-The-Snow-Bride-by-Debbie-Macomber.pdf
    • http://loaminoo.linkpc.net/1090096090096093099/St-Louis-Missouri-Bauwerk-in-St-Louis-Person-St-Louis-Sport-St-Louis-Olympische-Sommerspiele-1904-Marilyn-Vos-Savant-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/6096094096098092/Les-Rois-de-France-Louis-XIII-Louis-XIV-Louis-XV-Louis-XVI-by-Jean-Christian-Petitfils.pdf
    • http://loaminoo.linkpc.net/1091099095094099098/Victory-in-Vietnam-by-William-Fox-Eckbert.pdf
    • http://loaminoo.linkpc.net/7097098094094095/Butterflies-of-the-Night-Mama-Sans-Geisha-Strippers-and-the-Japanese-Men-They-Serve-by-Lisa-Louis.pdf
    • http://loaminoo.linkpc.net/1091099095095090092/Lekt-reschl-ssel-Ludwig-Tieck-Der-blonde-Eckbert-by-Winfried-Freund.pdf
    • http://loaminoo.linkpc.net/3091094099090092/The-Man-from-Snowy-River-by-A-B-Paterson.pdf
    • http://loaminoo.linkpc.net/9094099093091091/Sharing-Snowy-by-Marilyn-Helmer.pdf
    • http://loaminoo.linkpc.net/4094093098098093/The-Snowy-Day-by-Ezra-Jack-Keats.pdf
    • http://loaminoo.linkpc.net/7091099091092094/Fox-Volant-of-the-Snowy-Mountain-by-Jin-Yong.pdf
    • http://loaminoo.linkpc.net/3092095091098093/The-Man-from-Snowy-River-and-Other-Verses-by-A-B-Paterson.pdf
    • http://loaminoo.linkpc.net/2090090090090096/A-Silly-Snowy-Day-by-Michael-Coleman.pdf
    • http://loaminoo.linkpc.net/6096094095091099/Snowy-Owls-amp-Battered-Bulbuls-by-Richard-Brigham.pdf
    • http://loaminoo.linkpc.net/9097094097091092/Zooey-It-s-Snowy-A-Holiday-Adventure-by-Melissa-Natasi.pdf
    • http://loaminoo.linkpc.net/3097094095099091/A-Snowy-Christmas-in-Wyoming-Creeds-Crossing-1-by-E-Ayers.pdf
    • http://loaminoo.linkpc.net/1095092090098095/The-Girl-from-Snowy-River-Matilda-Saga-2-by-Jackie-French.pdf
    • http://loaminoo.linkpc.net/4091097097091092/The-Deep-and-Snowy-Wood-Christmas-Picture-Book-by-Elwyn-Tate.pdf
    • http://loaminoo.linkpc.net/8093094093092095/Si-cle-de-Louis-XIV-Vol-1-Auquel-on-a-Joint-Un-Pr-cis-Du-Si-cle-de-Louis-XV-Et-Un-Autre-Morceau-D-Histoire-by-Voltaire.pdf
    • http://loaminoo.linkpc.net/7096091092091/Ride-the-River-Louis-Lamour-Collection-by-Louis-L-39-Amour.pdf
    • http://loaminoo.linkpc.net/1091095098097099098/Translations-from-the-German-Mus-us-Dumb-Love-Libussa-Melechsala-Tieck-The-Fair-Haired-Eckbert-the-Trusty-Eckart-the-Runenberg-the-Elves-the-Goblet-Richter-Schmelzel-s-Journey-to-FL-Tz-Life-of-Quintus-Fixlein-by-Johann-Wolfgang-von-Goethe.pdf