Malicious PDF — malware analysis report

Static analysis result for SHA-256 30adb31b796ac871…

MALICIOUS

PDF

20.7 KB Created: 2019-05-02 05:11:27 +01:00 Authoring application: mPDF 5.7
MD5: 4e2d3768d5c266453c1b6f3d8da06588 SHA-1: 85451137a72d03a27f6bf6c85f96b6b0fae9e66c SHA-256: 30adb31b796ac8716387b5878305407b4aca61d62edd2f554700192027e86852
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on loaminoo.linkpc.net. While the URLs themselves are marked as benign, the sheer volume and nature of the links suggest a potential SEO manipulation or a distribution mechanism for other malicious content. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific intent.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4093092097092/A-Dragon-s-Awakening-The-Chronicles-of-Kale-1-by-Aya-Knight.pdf
    • http://loaminoo.linkpc.net/2091098093098092/The-Dragon-Knight-Dragon-Knight-2-by-Gordon-R-Dickson.pdf
    • http://loaminoo.linkpc.net/4098098096097091/The-Dragon-Knight-Dragon-Knight-2-by-Gordon-R-Dickson.pdf
    • http://loaminoo.linkpc.net/7095099092098/Killing-Sam-Knight-The-Knight-Chronicles-2-by-John-Cassian.pdf
    • http://loaminoo.linkpc.net/2091092095099095/Flight-of-the-Dragon-Kyn-Dragon-Chronicles-2-by-Susan-Fletcher.pdf
    • http://loaminoo.linkpc.net/2099099092095098/Dragon-s-Milk-Dragon-Chronicles-1-by-Susan-Fletcher.pdf
    • http://loaminoo.linkpc.net/2097099092094/Dragon-s-Blood-Pit-Dragon-Chronicles-1-by-Jane-Yolen.pdf
    • http://loaminoo.linkpc.net/4095092091093090/Dances-With-Sheep-A-K-Chronicles-Compendium-K-Chronicles-1-by-Keith-Knight.pdf
    • http://loaminoo.linkpc.net/2090096093098098/The-Dragon-Mate-s-Awakening-Dragongrove-3-by-Imogen-Sera.pdf
    • http://loaminoo.linkpc.net/1097092095093092/The-Rain-Wilds-Chronicles-Dragon-Keeper-Dragon-Haven-City-of-Dragons-and-Blood-of-Dragons-by-Robin-Hobb.pdf
    • http://loaminoo.linkpc.net/2099095092094094/Dragon-Outcast-Age-of-Fire-3-by-E-E-Knight.pdf
    • http://loaminoo.linkpc.net/2099095092094095/Dragon-Avenger-Age-of-Fire-2-by-E-E-Knight.pdf
    • http://loaminoo.linkpc.net/4093097094097093/Sleepwalker-Chronicles-The-Awakening-by-Lillith-Black.pdf
    • http://loaminoo.linkpc.net/3099091096095098/Dragon-Knight-s-Shield-by-Mary-Morgan.pdf
    • http://loaminoo.linkpc.net/1096097091093099/Awakening-The-Elder-Chronicles-Volume-1-by-Scott-Wieczorek.pdf
    • http://loaminoo.linkpc.net/1091091097097090099/Neon-Dragon-Knight-and-Devlin-1-by-John-F-Dobbyn.pdf
    • http://loaminoo.linkpc.net/3097094092096097/G-A-Aiken-Dragon-Bundle-The-Dragon-Who-Loved-Me-What-a-Dragon-Should-Know-Last-Dragon-Standing-amp-How-to-Drive-a-Dragon-Crazy-The-Dragon-Kin-3-6-by-G-A-Aiken.pdf
    • http://loaminoo.linkpc.net/1098095096098090/The-Conan-Chronicles-Volume-2-The-Hour-of-the-Dragon-The-Conan-Chronicles-2-by-Robert-E-Howard.pdf
    • http://loaminoo.linkpc.net/4099093097095099/Dragon-Prince-Series-Including-Melanie-Rawn-Dragon-Prince-Sunrunner-s-Fire-the-Star-Scroll-Sunrunner-High-Prince-Stronghold-Novel-the-Dragon-Token-Skybowl-Dragon-Prince-and-Dragon-Star-Trilogies-Diarmadhi-Merida-Dragon-Prince-Isulk-im-by-Hephaestus-Books.pdf
    • http://loaminoo.linkpc.net/1090099098095094/Escapement-The-Neumarian-Chronicles-1-by-Ciara-Knight.pdf
    • http://loaminoo.linkpc.net/1097092095093092/The-Rain-Wilds-Chr