Malicious PDF — malware analysis report

Static analysis result for SHA-256 319c05188a6f977b…

MALICIOUS

PDF

14.3 KB Created: 2019-04-30 03:18:46 +01:00 Authoring application: mPDF 5.7
MD5: 45655b1a9afbbf587e52571ec9eb7d0d SHA-1: bdb298a89444eac7d2963d1a1e014f270bbcc7a0 SHA-256: 319c05188a6f977b59f84367bf9c5480185a49497f079ec2c6a293b318904eff
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the 'loaminoo.linkpc.net' domain. While the URLs themselves are marked as confirmed benign, the sheer volume and structure suggest a potential link farm or distribution mechanism for malicious content, possibly disguised as legitimate documents. No scripts were extracted, limiting further analysis of the file's direct execution capabilities.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2096095096094097/Forever-Betrayed-Forever-Bluegrass-3-by-Kathleen-Brooks.pdf
    • http://loaminoo.linkpc.net/2099094098099096/Forever-Hidden-Forever-Bluegrass-2-by-Kathleen-Brooks.pdf
    • http://loaminoo.linkpc.net/2096095096094090/Forever-Surprised-Forever-Bluegrass-6-by-Kathleen-Brooks.pdf
    • http://loaminoo.linkpc.net/3099095095095090/All-Hung-Up-Bluegrass-Singles-1-by-Kathleen-Brooks.pdf
    • http://loaminoo.linkpc.net/1097093092098093/Final-Vow-Bluegrass-Brothers-6-by-Kathleen-Brooks.pdf
    • http://loaminoo.linkpc.net/1094094094096090/Rising-Storm-Bluegrass-Brothers-2-by-Kathleen-Brooks.pdf
    • http://loaminoo.linkpc.net/1091090099091094/A-Faerie-Fated-Forever-Forever-1-by-Mary-Anne-Graham.pdf
    • http://loaminoo.linkpc.net/3098091097092094/A-Faerie-Fated-Forever-Forever-1-by-Mary-Anne-Graham.pdf
    • http://loaminoo.linkpc.net/1092097096091093/The-Truth-About-Forever-The-Forever-Series-Book-1-by-Cole-Lepley.pdf
    • http://loaminoo.linkpc.net/3094097099095097/Planning-on-Forever-The-Forever-Series-1-by-Ashley-Wilcox.pdf
    • http://loaminoo.linkpc.net/2090091090091090/Dying-Forever-Waking-Forever-4-by-Heather-McVea.pdf
    • http://loaminoo.linkpc.net/4099098094098093/Together-Forever-Caitlin-Forever-Trilogy-3-by-Francine-Pascal.pdf
    • http://loaminoo.linkpc.net/1099092095093090/The-Rest-of-Forever-Firsts-and-Forever-16-by-Alexa-Land.pdf
    • http://loaminoo.linkpc.net/5096096097094093/Promising-Forever-Forever-3-by-Ashley-Wilcox.pdf
    • http://loaminoo.linkpc.net/2098091091099095/The-Forever-Trilogy-Forever-1-3-by-Sandi-Lynn.pdf
    • http://loaminoo.linkpc.net/4091091094092098/A-Broken-Forever-Forever-1-by-Megan-Noelle.pdf
    • http://loaminoo.linkpc.net/4090099097098/Forever-Us-Forever-3-by-Sandi-Lynn.pdf
    • http://loaminoo.linkpc.net/5092099093096090/The-Forever-War-Forever-Free-by-Joe-Haldeman.pdf
    • http://loaminoo.linkpc.net/1095094097097092/Forever-Free-The-Forever-War-3-by-Joe-Haldeman.pdf
    • http://loaminoo.linkpc.net/9092094096092090/Saving-Forever---Part-5-Saving-Forever-5-by-Lexy-Timms.pdf
    • http://loaminoo.linkpc.net/1099092095093090/The-Rest-of-Forever-Firsts-and-Forever-16-by