Malicious PDF — malware analysis report

Static analysis result for SHA-256 396bf0700f130dd1…

MALICIOUS

PDF

18.2 KB Created: 2019-05-07 04:38:49 +01:00 Authoring application: mPDF 5.7
MD5: 508b7952b44c86d026586e4dddbf45b9 SHA-1: e41dff3220377661219d65079be11e1ff13342de SHA-256: 396bf0700f130dd108297bc9d6876f960ee21c4e2ed61cb1b1a153ef138e9651
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This is indicative of a link farm or SEO poisoning attack, designed to drive traffic or potentially distribute further malicious content. While no scripts were extracted, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. The document body itself is heavily corrupted, preventing analysis of its direct content.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1098099091097099/A-Single-Swallow-Following-An-Epic-Journey-From-South-Africa-To-South-Wales-by-Horatio-Clare.pdf
    • http://loaminoo.linkpc.net/6090095096098097/Rum-Rebellion-A-Study-Of-The-Overthrow-Of-Governor-Bligh-By-John-Macarthur-And-The-New-South-Wales-Corps-by-H-V-Evatt.pdf
    • http://loaminoo.linkpc.net/5090093090098094/Christmas-Every-Day-by-William-Dean-Howells.pdf
    • http://loaminoo.linkpc.net/4095097091092099/A-Traveler-from-Altruria-by-William-Dean-Howells.pdf
    • http://loaminoo.linkpc.net/7091097094096098/Stories-of-Ohio-by-William-Dean-Howells.pdf
    • http://loaminoo.linkpc.net/1098099098097099/Rees-Howells-Intercessor-by-Norman-P-Grubb.pdf
    • http://loaminoo.linkpc.net/1093092097093094/The-Landlord-at-Lion-s-Head-by-William-Dean-Howells.pdf
    • http://loaminoo.linkpc.net/1091096093091092/The-Rise-of-Silas-Lapham-by-William-Dean-Howells.pdf
    • http://loaminoo.linkpc.net/1091094092095092/When-the-Alps-Cast-Their-Spell-Mountaineers-of-the-Alpine-Golden-Age-by-Trevor-Braham.pdf
    • http://loaminoo.linkpc.net/1094092092094090/Children-of-Crisis-Volume-2-Migrants-Sharecroppers-Mountaineers-by-Robert-Coles.pdf
    • http://loaminoo.linkpc.net/2095094098094091/The-South-vs-The-South-How-Anti-Confederate-Southerners-Shaped-the-Course-of-the-Civil-War-by-William-W-Freehling.pdf
    • http://loaminoo.linkpc.net/1091094092097091/Cold-Feet-Stories-of-a-Middling-Climber-On-Classic-Peaks-amp-Among-Legendary-Mountaineers-by-David-Pagel.pdf
    • http://loaminoo.linkpc.net/4095091099090096/Guns-Drugs-and-Coconuts-South-Pacific-and-South-East-Asia-by-John-Frederick-Dixon.pdf
    • http://loaminoo.linkpc.net/1091098091090090093/Far-East-Down-South-Asians-in-the-American-South-by-Raymond-A-Mohl.pdf
    • http://loaminoo.linkpc.net/7097099097099092/Ignorant-Bliss-by-Brendan-Lee.pdf
    • http://loaminoo.linkpc.net/7097099097098099/Ignorant-Armies-by-Sam-Wharton.pdf
    • http://loaminoo.linkpc.net/7097099099090099/Stories-for-an-Ignorant-Man-by-Ina-Disguise.pdf
    • http://loaminoo.linkpc.net/7097099097097091/Ignorant-Armies-by-David-Pringle.pdf
    • http://loaminoo.linkpc.net/7097099097099091/Ignorant-Armies-by-Karen-Alkalay-Gut.pdf
    • http://loaminoo.linkpc.net/7097099099091098/You-re-Not-Stupid-You-re-Ignorant-by-Lance-Hodge.pdf
    • http://loaminoo.linkpc.net/10930920