Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dbd57c1fec9ff5d…

MALICIOUS

PDF

13.8 KB Created: 2019-04-30 02:02:40 +01:00 Authoring application: mPDF 5.7
MD5: 4c29161b97ba4aa5c992bb74698f46b2 SHA-1: f8737fc241855a041ce0dd886af80cc3bc75ffb5 SHA-256: 9dbd57c1fec9ff5d4d00411add9c1a8fab9c0cc9096298eaaa6f450c16c84277
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links all point to the same domain, loaminoo.linkpc.net, and appear to be designed to direct users to external content. The embedded URLs are likely part of a phishing or redirection scheme to a malicious site. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4092095093095095/Binding-Cause-by-L-P-Lindeman.pdf
    • http://loaminoo.linkpc.net/1091096098090096092/The-Binding-by-Victoria-Clapton.pdf
    • http://loaminoo.linkpc.net/1091096098091094094/Binding-a-Demon-by-Megan-Derr.pdf
    • http://loaminoo.linkpc.net/7093093096093098/Harmonica-s-Bridegroom-by-Paul-Binding.pdf
    • http://loaminoo.linkpc.net/1091096098090096091/The-Binding-Song-by-Elodie-Harper.pdf
    • http://loaminoo.linkpc.net/1091096098091095097/Spells-of-Binding-Liavek-4-by-Will-Shetterly.pdf
    • http://loaminoo.linkpc.net/4093094092092090/Binding-Ecstasy-Guardians-of-the-Realms-6-by-Setta-Jay.pdf
    • http://loaminoo.linkpc.net/1091096098091094098/The-Binding-The-Luminated-Threads-3-by-Laurel-Wanrow.pdf
    • http://loaminoo.linkpc.net/4097098095093096/Binding-the-Baroness-Cavern-of-Pleasures-3-by-Em-Brown.pdf
    • http://loaminoo.linkpc.net/1096091092094095/Binding-the-Edges-Tales-from-the-Edge-8-by-L-M-Somerton.pdf
    • http://loaminoo.linkpc.net/6094095090090/Binding-the-Shadows-Arcadia-Bell-3-by-Jenn-Bennett.pdf
    • http://loaminoo.linkpc.net/2096098093093099/Binding-the-Shadows-Arcadia-Bell-3-by-Jenn-Bennett.pdf
    • http://loaminoo.linkpc.net/1091096098091090094/Binding-Spell-Tales-of-the-Latter-Kingdoms-3-by-Christine-Pope.pdf
    • http://loaminoo.linkpc.net/6099090095091091/Introduction-to-Government-and-Binding-Theory-by-Liliane-M-V-Haegeman.pdf
    • http://loaminoo.linkpc.net/3093098094094097/Island-Colonization-The-Origin-and-Development-of-Island-Communities-by-Ian-Thornton.pdf
    • http://loaminoo.linkpc.net/5090095099094099/I-is-for-Island-A-Prince-Edward-Island-Alphabet-by-Hugh-Macdonald.pdf
    • http://loaminoo.linkpc.net/2091094099091099/The-Three-Inch-Golden-Lotus-A-Novel-on-Foot-Binding-by-Feng-Jicai.pdf
    • http://loaminoo.linkpc.net/3098096098095099/The-House-of-Binding-Thorns-Dominion-of-the-Fallen-2-by-Aliette-de-Bodard.pdf
    • http://loaminoo.linkpc.net/4096098098098094/Binding-Magick-The-Witch-Blood-Chronicles-1-by-Debbie-Cassidy.pdf
    • http://loaminoo.linkpc.net/6094090099092096/Island-Healing-St-Anne-s-Island-1-by-Virginia-McCullough.pdf
    • http://loaminoo.linkpc.net/1091096098091090094/Binding-Spell-Tales-of-the-Latter-Kingdoms-3-by-Christine-