Malicious PDF — malware analysis report

Static analysis result for SHA-256 89e81b28f3e9dc1d…

MALICIOUS

PDF

25.0 KB Created: 2019-04-30 03:30:01 +01:00 Authoring application: mPDF 5.7
MD5: 62d3a64b2413f20976754e4bded39cd5 SHA-1: 20fc99d4cf5c75b089e7659d158e0b78b4d109c1 SHA-256: 89e81b28f3e9dc1dfad3177c3caae4785c1522bb19492ad24039843003463e41
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a mechanism to distribute malicious content indirectly. While the document body itself is heavily obfuscated and does not provide clear textual lures, the heuristic 'PDF_SEO_LINK_FARM' strongly suggests malicious intent through the sheer volume and nature of the linked content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1091093093098090098/Gone-Walkabout-in-Henn-Boo-Too-by-William-P-Hogan.pdf
    • http://loaminoo.linkpc.net/1091093093098091090/Daily-Inspiration-From-Kathy-Henn-Positive-Feelings-Series-Book-1-by-Kathy-Henn.pdf
    • http://loaminoo.linkpc.net/1091093093098094092/Daily-Inspiration-From-Kathy-Henn-Positive-Feelings-Book-4-by-Kathy-Henn.pdf
    • http://loaminoo.linkpc.net/3093099099092090/The-Theology-And-Spirituality-of-Mary-Tudor-s-Church-by-William-Wizeman.pdf
    • http://loaminoo.linkpc.net/7096091093097090/Curlew-River----A-Parable-for-Church-Performance-Op-71-Libretto-by-William-Plomer.pdf
    • http://loaminoo.linkpc.net/9094097091095097/The-Bohlen-Lectures-for-1891-the-Peace-of-the-Church-by-William-Reed-Huntington.pdf
    • http://loaminoo.linkpc.net/7090099098093096/The-Manifesto-Church-Records-of-the-Church-in-Brattle-Square-Boston-with-Lists-of-Communicants-Baptisms-Marriages-and-Funerals-1699-1872-by-Church-in-Brattle-Square.pdf
    • http://loaminoo.linkpc.net/6096099095095093/Historical-Sketch-of-Bruton-Church-Williamsburg-Virginia-by-William-Archer-Rutherfoord-Goodwin.pdf
    • http://loaminoo.linkpc.net/7090099098094091/The-Manifesto-Church-Records-of-the-Church-in-Brattle-Square-Boston-With-Lists-of-Communicants-Baptisms-Marriages-and-Funerals-1699-1872-by-Church-in-Brattle-Square-Boston.pdf
    • http://loaminoo.linkpc.net/5094092090097092/Church-Charism-and-Power-Liberation-Theology-and-the-Institutional-Church-by-Leonardo-Boff.pdf
    • http://loaminoo.linkpc.net/4096091093098/The-Book-of-Common-Prayer-and-Administration-of-the-Sacraments-and-Other-Rites-and-Ceremonies-of-the-Church-by-Church-of-England.pdf
    • http://loaminoo.linkpc.net/4092092092094093/Rediscovered-Early-Church-PreMillennialism-Teachings-of-the-Earliest-Church-Fathers-on-Prophecy-by-Robert-H-Franklin.pdf
    • http://loaminoo.linkpc.net/6091090097095093/Vertical-Church-What-Every-Heart-Longs-For-What-Every-Church-Can-Be-by-James-MacDonald.pdf
    • http://loaminoo.linkpc.net/3096090099097097/The-Purpose-Driven-Church-Every-Church-Is-Big-in-God-s-Eyes-by-Rick-Warren.pdf
    • http://loaminoo.linkpc.net/7090098097098095/The-Church-of-God-Or-Essays-on-Various-Names-and-Titles-Given-to-the-Church-in-the-Holy-Scriptures-To-Which-Are-Added-Some-Papers-on-Other-Subjects-by-Ambrose-Serle.pdf
    • http://loaminoo.linkpc.net/7090098098091092/The-Church-of-God-Or-Essays-on-Various-Names-and-Titles-Given-to-the-Church-in-the-Holy-Scriptures-To-Which-Are-Added-Some-Papers-on-Other-Subjects-by-Ambrose-Serle.pdf
    • http://loaminoo.linkpc.net/4091093093090096/Church-History-Volume-One-From-Christ-to-Pre-Reformation-The-Rise-and-Growth-of-the-Church-in-Its-Cultural-Intellectual-and-Political-Context-by-Everett-Ferguson.pdf
    • http://loaminoo.linkpc.net/1091093093098094093/Bedtime-with-Ted-by-Sophy-Henn.pdf
    • http://loaminoo.linkpc.net/1091093093099094099/Playtime-with-Ted-by-Sophy-Henn.pdf
    • http://loaminoo.linkpc.net/1091093093099094092/The-Harvest-of-Tragedy-by-T-R-Henn.pdf
    • http://loaminoo.linkpc.net/7090099098093096/The-Manifesto-Church-Recor