Malicious PDF — malware analysis report

Static analysis result for SHA-256 503934faea91490e…

MALICIOUS

PDF

15.6 KB Created: 2019-04-30 04:06:27 +01:00 Authoring application: mPDF 5.7
MD5: 820950e701b5214c29dd38fee0663a10 SHA-1: 721aef8c0970ae8c25bb7e8e710eed55f9aad74f SHA-256: 503934faea91490e915cd16c145c4fd4a934063b28d9f2e0fbf068719c3ce579
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a PDF_SEO_LINK_FARM heuristic. These URLs point to various PDF documents hosted on loaminoo.linkpc.net. While the individual URLs are currently marked as confirmed_benign, the sheer volume and the nature of the heuristic suggest a malicious intent, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4099098098092094/Spear-Hunter-by-Henry-J-Olsen.pdf
    • http://loaminoo.linkpc.net/1097094093097097/Spear---A-Spear-in-Flight-Spear-1-by-Douglas-Owen.pdf
    • http://loaminoo.linkpc.net/4094091093099099/I-Was-a-Teenage-Ghost-Hunter-by-Brian-K-Henry.pdf
    • http://loaminoo.linkpc.net/7098099097095097/Myths-about-socialism-H-vard-Olsen-by-H-vard-Olsen.pdf
    • http://loaminoo.linkpc.net/3098099094093/The-Guardian-Dark-Hunter-20-Dream-Hunter-5-Were-Hunter-6-Hellchaser-3-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/1093095091098095/Redemption-Dark-Hunter-20-5-Dream-Hunter-5-5-Were-Hunter-6-5-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/5098099098090095/Hunter-x-Hunter-Vol-19-Hunter-x-Hunter-19-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/5098099098091094/Hunter-x-Hunter-Vol-28-Hunter-x-Hunter-28-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/3099092090096/Hunter-x-Hunter-Vol-01-Hunter-x-Hunter-1-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/5098099098091093/Hunter-x-Hunter-Vol-27-Hunter-x-Hunter-27-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/5098099098097090/Hunter-x-Hunter-Vol-23-Hunter-x-Hunter-23-by-Yoshihiro-Togashi.pdf
    • http://loaminoo.linkpc.net/3090091091091095/Dark-Bites-Dream-Hunter-1-Hellchaser-1-Were-Hunter-1-Dark-Hunter-2-5-2-6-7-5-9-5-9-6-10-5-by-Sherrilyn-Kenyon.pdf
    • http://loaminoo.linkpc.net/6097094090091098/Libertine-by-Peta-Spear.pdf
    • http://loaminoo.linkpc.net/4098094093095091/The-Spear-by-James-Herbert.pdf
    • http://loaminoo.linkpc.net/1092091094094098/Escape-Tip-of-the-Spear-1-by-Belle-Ami.pdf
    • http://loaminoo.linkpc.net/2092096092097096/Dar-And-The-Spear-Thrower-by-Marjorie-Cowley.pdf
    • http://loaminoo.linkpc.net/9091096097091095/The-Iron-Spear-by-Victoria-Kasten.pdf
    • http://loaminoo.linkpc.net/5090092091096096/Spear-Of-Destiny-by-Daniel-Easterman.pdf
    • http://loaminoo.linkpc.net/6099091093094097/The-Highlander-The-Highlanders-5-by-Terry-Spear.pdf
    • http://loaminoo.linkpc.net/2092095095095099/The-Spear-in-the-Sand-by-Raoul-C-Faure.pdf
    • http://loaminoo.linkpc.net/5098099098091093/Hunter-x-Hunter-Vol-27-Hunter-x-Hunter-27-by-Yoshihiro-Togashi.pd