Malicious PDF — malware analysis report

Static analysis result for SHA-256 31d97be8883afe6b…

MALICIOUS

PDF

13.4 KB Created: 2019-04-30 04:15:12 +01:00 Authoring application: mPDF 5.7
MD5: 92adb0caa7398ef1ff0bb53abd4aa04b SHA-1: e6ffa850cf4f833f61692e48ce23d0ebd28a96ec SHA-256: 31d97be8883afe6bbe43460084cc06891a6fcd477a88485cd35352add2cd9861
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various PDF documents hosted on the same domain, loaminoo.linkpc.net. While the individual URLs are marked as confirmed benign, the sheer volume and structure suggest a link farm or a mechanism for distributing further content, potentially malicious. No scripts were extracted from this sample. The attack pattern is inferred from the link farm structure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6092093096096098/Gigi-s-Guardian-by-Michele-McGrath.pdf
    • http://loaminoo.linkpc.net/1097096096095096/Mademoiselle-Gigi-Gigi-Series-1-by-Dennis-Ward.pdf
    • http://loaminoo.linkpc.net/6092093096090095/Mike-McGrath-s-Book-of-Compost-by-Mike-McGrath.pdf
    • http://loaminoo.linkpc.net/4093095098096099/The-Fallen-Guardian-The-Guardian-Chronicles-2-by-Steven-R-Burke.pdf
    • http://loaminoo.linkpc.net/2097097091098097/The-Last-Mage-Guardian-Guardian-s-Compact-1-by-Sabrina-Chase.pdf
    • http://loaminoo.linkpc.net/3096090091093098/The-Guardian-The-Guardian-Interviews-1-by-Michael-Clary.pdf
    • http://loaminoo.linkpc.net/2096098095093094/The-Guardian-s-Keeper-The-Guardian-Trilogy-1-by-T-R-Raven.pdf
    • http://loaminoo.linkpc.net/6097090098091091/If-I-Only-Knew-by-Gigi-Scott.pdf
    • http://loaminoo.linkpc.net/3094098091094098/Unforgettable-Able-3-by-Gigi-Aceves.pdf
    • http://loaminoo.linkpc.net/1091090094091092/Come-Fly-with-Me-Talon-1-by-Gigi-Sedlmayer.pdf
    • http://loaminoo.linkpc.net/4098095097097090/La-Tiers-Du-Cylindre-by-Gigi.pdf
    • http://loaminoo.linkpc.net/1096093/The-Accidental-Alchemist-by-Gigi-Pandian.pdf
    • http://loaminoo.linkpc.net/9093096099097096/The-Intentions-Book-by-Gigi-Fenster.pdf
    • http://loaminoo.linkpc.net/9091096093099097/Belt-Buckles-and-Spurs-by-Gigi-Thorne.pdf
    • http://loaminoo.linkpc.net/1098097093096096/The-Starter-Wife-by-Gigi-Levangie-Grazer.pdf
    • http://loaminoo.linkpc.net/3092096096090099/Mud-Stories-of-Sex-and-Love-Michele-Roberts-by-Mich-le-Roberts.pdf
    • http://loaminoo.linkpc.net/4095098099096092/Your-Guardian-Angel-Guardian-Angel-1-by-Skyla-Madi.pdf
    • http://loaminoo.linkpc.net/2092095095090094/The-Moon-Burns-Gigi-Monroe-2-by-Angela-Horn.pdf
    • http://loaminoo.linkpc.net/6097094095092092/Extra-Credit-A-Teacher-amp-Student-Romance-by-Gigi-Thorne.pdf
    • http://loaminoo.linkpc.net/8096099094097092/Winning-Ways-for-Early-Childhood-Professionals-Being-a-Professional-by-Gigi-Schweikert.pdf
    • http://loaminoo.linkpc.net/9093096099097096/The-Int