Malicious PDF — malware analysis report

Static analysis result for SHA-256 582d4a8c216ec2a5…

MALICIOUS

PDF

13.3 KB Created: 2019-04-30 02:40:48 +01:00 Authoring application: mPDF 5.7
MD5: 8ab16b6b00968e0417ad453707c62dea SHA-1: 614845999a57984e68325a173b564e6bf059bd7d SHA-256: 582d4a8c216ec2a5a02ef46eccd43a4b31261ee7ed34110b6ec4810af63ac319
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various PDF documents hosted on loaminoo.linkpc.net. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a potential SEO manipulation or content distribution scheme. No scripts were extracted, and the document body is heavily corrupted, limiting further analysis of the specific lure.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1099099092097093/Remember-Me-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/2095097096093099/Truth-Or-Lie-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/2095097098099090/Coliseum-Square-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/3092098098090090/No-Good-Deed-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/1096091091094094/His-Duke-s-Gift-In-The-Company-Of-Men-5-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/4091098099093099/Jackson-s-Pride-In-the-Company-of-Men-2-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/4097098091093098/Silent-Lodge-In-the-Company-of-Men-4-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/2093095095091091/Soul-Bonds-Common-Powers-1-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/2098095099090095/Edward-Unconditionally-Common-Powers-3-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/3095093097092096/Bayou-Loup-Rougaroux-Social-Club-3-by-Lynn-Lorenz.pdf
    • http://loaminoo.linkpc.net/3097097091092095/Adwaka-s-Blade-Lady-Blue-Crew-4-by-Lynn-Hagen.pdf
    • http://loaminoo.linkpc.net/3095092095099097/The-Hidden-Blade-The-Heart-of-Blade-Duology-1-by-Sherry-Thomas.pdf
    • http://loaminoo.linkpc.net/3092096099090096/Bared-Blade-Fallen-Blade-2-by-Kelly-McCullough.pdf
    • http://loaminoo.linkpc.net/3092098092090098/Blade-Reforged-Fallen-Blade-4-by-Kelly-McCullough.pdf
    • http://loaminoo.linkpc.net/2095096094095/Blade-on-the-Hunt-Goddess-With-A-Blade-3-by-Lauren-Dane.pdf
    • http://loaminoo.linkpc.net/1099096093093094/Blade-to-the-Keep-Goddess-With-A-Blade-2-by-Lauren-Dane.pdf
    • http://loaminoo.linkpc.net/1091092092094099099/The-Correspondence-of-John-Locke-3-Letters-849-1241-1686-89-by-John-Locke.pdf
    • http://loaminoo.linkpc.net/2098095096096099/The-Name-of-the-Blade-The-Name-of-the-Blade-1-by-Zo-Marriott.pdf
    • http://loaminoo.linkpc.net/7096092091099095/Angel-Blade-Angel-Blade-1-by-Carrie-Merrill.pdf
    • http://loaminoo.linkpc.net/1095096093099091/The-Queen-s-Blade-The-Queen-s-Blade-1-by-T-C-Southwell.pdf
    • http://loaminoo.linkpc.net/3092098092090098/Blade-Reforged-Fallen-Blade-4-by-Kelly-McCulloug