Malicious PDF — malware analysis report

Static analysis result for SHA-256 39ad32f2e28b888f…

MALICIOUS

PDF

17.9 KB Created: 2019-05-03 05:44:22 +01:00 Authoring application: mPDF 5.7
MD5: 3e2af4654db8f7881e4307c2e3eb24f8 SHA-1: dc231f79a64a6d6ae02cadd10d8429089de46b76 SHA-256: 39ad32f2e28b888f3a8eb2a33892b868853cf80a0e1e4a98dd25c4a6c3344822
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This heuristic firing indicates a link farm, likely intended to drive traffic or host malicious content disguised as legitimate documents. No scripts were extracted, and the document body is heavily obfuscated, but the sheer volume of links suggests a malicious intent to redirect the user. The URLs themselves are the primary IOCs.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7094091096094091/The-Best-of-Cordwainer-Smith-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091097094098/No-No-Not-Rogov-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091096099094/Three-to-a-Given-Star-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091096093097/Stardreamer-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/4097098091093/The-Instrumentality-of-Mankind-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091096098097/The-Colonel-Came-Back-From-the-Nothing-at-All-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091097094097/The-Burning-of-the-Brain-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091096093093/Under-Old-Earth-And-Other-Explorations-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091097094096/The-Queen-of-the-Afternoon-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091097096092/On-the-Storm-Planet-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091097095096/Die-K-nigin-des-Nachmittags-Erz-hlung-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091095097093/Short-Stories-by-Cordwainer-Smith-by-Books-LLC.pdf
    • http://loaminoo.linkpc.net/7094091096093094/Mother-Hitton-s-Littul-Kittons-by-Cordwainer-Smith.pdf
    • http://loaminoo.linkpc.net/7094091096094094/The-Game-of-Rat-and-Dragon-by-Cordwainer-Smith-by-Super-Large-Print.pdf
    • http://loaminoo.linkpc.net/7094091098096099/American-Military-Writers-Stephen-E-Ambrose-Oliver-North-Tom-Clancy-John-McCain-Hunter-Scott-P-G-T-Beauregard-Cordwainer-Smith-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/8099093098097/The-Quest-Ancient-Egypt-4-by-Wilbur-Smith.pdf
    • http://loaminoo.linkpc.net/2097098094097095/Wren-s-Quest-Wren-2-by-Sherwood-Smith.pdf
    • http://loaminoo.linkpc.net/2092092091098096/Worlds-Together-Worlds-Apart-A-History-of-the-World-from-the-Beginnings-of-Humankind-to-the-Present-by-Robert-L-Tignor.pdf
    • http://loaminoo.linkpc.net/9096094090097/Journey-Back-To-Threa-Old-Worlds-amp-New-Worlds-Trilogy-Book-1-by-Cindy-Larie-Rowell-Cowles.pdf
    • http://loaminoo.linkpc.net/3093094096092099/Journey-Back-To-Threa-Old-Worlds-amp-New-Worlds-Trilogy-Book-1-by-Cindy-Larie-Rowell-Cowles.pdf
    • http://loaminoo.linkpc.net/7094091096093094/Moth