Malicious PDF — malware analysis report

Static analysis result for SHA-256 7fcbfd663d221452…

MALICIOUS

PDF

16.5 KB Created: 2019-04-30 04:07:59 +01:00 Authoring application: mPDF 5.7
MD5: 883d5ae89bd00ddc1b07810ab9d5da41 SHA-1: 0e08528b846493ba78fff4a5457a5a1b607bc2e3 SHA-256: 7fcbfd663d221452e9dc2fc408edead0fc20917e0d2760bb4b67fe415331da6e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on the `loaminoo.linkpc.net` domain. While the URLs themselves are currently marked as benign, the sheer volume and the nature of the heuristic suggest a potential SEO manipulation scheme or a link farm designed to distribute malicious content or traffic. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.n
    • http://loaminoo.linkpc.net/3096092097091090/The-Stone-Demon-The-Iron-Witch-3-by-Karen-Mahoney.pdf
    • http://loaminoo.linkpc.net/3092098095092094/The-Wood-Queen-The-Iron-Witch-2-by-Karen-Mahoney.pdf
    • http://loaminoo.linkpc.net/3091096099090095/Falling-to-Ash-Moth-1-by-Karen-Mahoney.pdf
    • http://loaminoo.linkpc.net/9094099091091097/Iron-Fey-Series-Volume-1-The-Iron-King-Winter-s-Passage-The-Iron-Daughter-The-Iron-Queen-Summer-s-Crossing-by-Julie-Kagawa.pdf
    • http://loaminoo.linkpc.net/2099094098090097/The-Witch-Stone-Court-of-Ash-and-Stone-1-by-Jasmine-Hong.pdf
    • http://loaminoo.linkpc.net/3099091096099095/Iron-Man-Demon-in-a-Bottle-by-David-Michelinie.pdf
    • http://loaminoo.linkpc.net/8098091098/The-Iron-Flower-The-Black-Witch-Chronicles-2-by-Laurie-Forest.pdf
    • http://loaminoo.linkpc.net/3095097093090096/Demon-Dance-Vampire-Gene-3-by-Sam-Stone.pdf
    • http://loaminoo.linkpc.net/3099091090098093/The-Vanishing-Witch-by-Karen-Maitland.pdf
    • http://loaminoo.linkpc.net/1091090093097093/Four-Rubbings-The-Stone-Witch-1-by-Jennifer-L-Hotes.pdf
    • http://loaminoo.linkpc.net/1096098098093099/The-Witch-Awakening-The-Landers-Saga-1-by-Karen-Nilsen.pdf
    • http://loaminoo.linkpc.net/1091095096091/Witch-Bound-Twilight-of-the-Gods-2-by-Eleri-Stone.pdf
    • http://loaminoo.linkpc.net/1092090093093093/My-Enemy-s-Tears-The-Witch-of-Northampton-by-Karen-Vorbeck-Williams.pdf
    • http://loaminoo.linkpc.net/1096093097091091/The-Stone-Forest-by-Karen-Harper.pdf
    • http://loaminoo.linkpc.net/3092096092090099/Stone-Mad-Karen-Memory-2-by-Elizabeth-Bear.pdf
    • http://loaminoo.linkpc.net/1092099092097098/The-Last-Victim-Dr-Charlotte-Stone-1-by-Karen-Robards.pdf
    • http://loaminoo.linkpc.net/8098095091099/The-Last-Kiss-Goodbye-Dr-Charlotte-Stone-2-by-Karen-Robards.pdf
    • http://loaminoo.linkpc.net/4091097095097095/Water-Witch-Blood-Witch-Bone-Witch-Witches-of-Etlantium-1-3-by-Thea-Atkinson.pdf
    • http://loaminoo.linkpc.net/8092092095092098/Iron-Rails-Iron-Men-and-the-Race-to-Link-the-Nation-The-Story-of-the-Transcontinental-Railroad-by-Martin-W-Sandler.pdf
    • http://loaminoo.linkpc.net/1097098098092095/Iron-amp-Wine-The-Iron-World-Series-1-by-Candace-Osmond.pdf