Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a31442bf00e3915…

MALICIOUS

PDF

16.7 KB Created: 2019-05-02 17:26:13 +01:00 Authoring application: mPDF 5.7
MD5: 7d01e1db928308fd8f02c5a18767a5be SHA-1: 43be116c9af8c6e750463def504bbacbf420ff32 SHA-256: 4a31442bf00e39152bc90a8347e294787630ffa9ae6eeecd14f462c2881baaa8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to a single domain, loaminoo.linkpc.net. This is indicative of a link farm or SEO manipulation tactic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic firing suggest a malicious intent to drive traffic or potentially distribute further malicious content disguised as book PDFs. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2092094094093095/Exodus-The-House-of-Silence-1-by-J-A-Jaken.pdf
    • http://loaminoo.linkpc.net/2096091099093092/Consort-The-House-of-Silence-3-by-J-A-Jaken.pdf
    • http://loaminoo.linkpc.net/7098097094092098/The-House-of-Silence-by-Blanca-Busquets.pdf
    • http://loaminoo.linkpc.net/5097094098092/House-of-Silence-by-Linda-Gillard.pdf
    • http://loaminoo.linkpc.net/2097090092096098/Poustinia-Encountering-God-in-Silence-Solitude-and-Prayer-Madonna-House-Classics-Vol-1-by-Catherine-de-Hueck-Doherty.pdf
    • http://loaminoo.linkpc.net/2093095095096099/Pathfinder-by-J-A-Jaken.pdf
    • http://loaminoo.linkpc.net/2096091099092095/His-Whipping-Boy-by-J-A-Jaken.pdf
    • http://loaminoo.linkpc.net/2094096099097097/Silence-Breaking-Storm-and-Silence-4-by-Robert-Thier.pdf
    • http://loaminoo.linkpc.net/3090098097098093/Silence-Part-Two-of-Echoes-amp-Silence-by-Angela-M-Hudson.pdf
    • http://loaminoo.linkpc.net/5097095096090/Broken-Silence-Silence-2-by-Natasha-Preston.pdf
    • http://loaminoo.linkpc.net/1091095090094090092/Breaking-the-Silence-Israelische-Soldaten-berichten-von-ihrem-Einsatz-in-den-besetzten-Gebieten-by-Breaking-the-Silence.pdf
    • http://loaminoo.linkpc.net/1090094097091099/Little-House-in-the-Big-Woods-Farmer-Boy-Little-House-on-the-Prairie-On-the-Banks-of-Plum-Creek-By-the-Shores-of-Silver-Lake-Little-House-1-5-by-Laura-Ingalls-Wilder.pdf
    • http://loaminoo.linkpc.net/7098093098094/Exodus-by-Anonymous.pdf
    • http://loaminoo.linkpc.net/1099090090092091/Excerpts-To-Exodus-by-The-Tru-Sum.pdf
    • http://loaminoo.linkpc.net/3092096099097/Exodus-by-Leon-Uris.pdf
    • http://loaminoo.linkpc.net/3093095093098092/Exodus-from-the-Seven-Cities-by-Jay-Brenham.pdf
    • http://loaminoo.linkpc.net/6093099091094094/Exodus-by-Leon-Uris.pdf
    • http://loaminoo.linkpc.net/3092091098090/Zenith-Exodus-2-by-Julie-Bertagna.pdf
    • http://loaminoo.linkpc.net/5097098095099099/Exodus-Apocalypsis-3-by-Elle-Casey.pdf
    • http://loaminoo.linkpc.net/4097090097096094/Aurora-Exodus-3-by-Julie-Bertagna.pdf
    • http://loaminoo.linkpc.net/109