Malicious PDF — malware analysis report

Static analysis result for SHA-256 a0fa43668afa6fc5…

MALICIOUS

PDF

18.8 KB Created: 2019-04-30 05:39:55 +01:00 Authoring application: mPDF 5.7
MD5: 6905e5e5d75cdd6b7b694889b4680cc2 SHA-1: 88566e80f4465e1da961d6e0025ec741527af63d SHA-256: a0fa43668afa6fc5c6c78c5e1115c3116c61bf47a1c96cf75f71e34ae087e39e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which are presented as book titles. These links all point to the same domain, loaminoo.linkpc.net, suggesting a coordinated effort to manipulate search engine results or drive traffic. No scripts were extracted from this sample. The primary attack pattern involves the mass distribution of external links within the document body.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo
    • http://loaminoo.linkpc.net/3098092094091090/The-Millionaire-Upstairs-by-M-J-O-39-Shea.pdf
    • http://loaminoo.linkpc.net/1096097092090090/The-Millionaire-s-Message-The-Homemade-Millionaire-s-Secrets-of-the-Rich-and-Free-by-Bryan-James.pdf
    • http://loaminoo.linkpc.net/8090090090097093/Millionaire-Mindset-HABITS-AND-SIMPLE-IDEAS-FOR-SUCCESS-YOU-CAN-START-NOW-Millionaire-Mind-Money-master-the-game-of-wealth-creation-by-successful-people-PROSPERITY-SUCCESS-SERIES-Book-2-by-Darnell-Smith.pdf
    • http://loaminoo.linkpc.net/1091095092096095090/The-Monk-Upstairs-by-Tim-Farrington.pdf
    • http://loaminoo.linkpc.net/1095090095094097/The-Merry-Millionaire-The-Merry-Millionaire-1-by-J-A-Wells.pdf
    • http://loaminoo.linkpc.net/3099090094094097/The-Upstairs-Room-by-Johanna-Reiss.pdf
    • http://loaminoo.linkpc.net/8095094092092098/Beethoven-Lives-Upstairs-by-Barbara-Nichol.pdf
    • http://loaminoo.linkpc.net/3097091093092098/Beethoven-Lives-Upstairs-by-Barbara-Nichol.pdf
    • http://loaminoo.linkpc.net/9092092090091093/Upstairs-Mouse-Downstairs-Mole-by-Wong-Herbert-Yee.pdf
    • http://loaminoo.linkpc.net/8095096092094090/Upstairs-Girls-Prostitution-in-the-American-West-by-Michael-Rutter.pdf
    • http://loaminoo.linkpc.net/8098099097099096/The-Lady-Upstairs-Dorothy-Schiff-and-the-New-York-Post-by-Marilyn-Nissenson.pdf
    • http://loaminoo.linkpc.net/3094093096096096/Servants-Hall-A-Real-Life-Upstairs-Downstairs-Romance-by-Margaret-Powell.pdf
    • http://loaminoo.linkpc.net/3094094091093090/Upstairs-amp-Downstairs-The-Illustrated-Guide-to-the-Real-World-of-Downton-Abbey-by-Sarah-Warwick.pdf
    • http://loaminoo.linkpc.net/1090097093092093099/Upstairs-at-the-Strand-Writers-in-Conversation-at-the-Legendary-Bookstore-by-Jessica-Strand.pdf
    • http://loaminoo.linkpc.net/4090096094095095/I-Want-to-be-a-Millionaire-by-Rajasaraswathii.pdf
    • http://loaminoo.linkpc.net/1098098093097090/An-Au-Pair-and-a-Millionaire-by-Eva-Goldsby.pdf
    • http://loaminoo.linkpc.net/7099096099095091/The-CEO-The-Millionaire-Malones-2-by-Victoria-Purman.pdf
    • http://loaminoo.linkpc.net/1097090096099098/How-To-Master-A-Millionaire-by-Talia-Hunter.pdf
    • http://loaminoo.linkpc.net/4097095097099091/An-Officer-and-a-Millionaire-by-Maureen-Child.pdf
    • http://loaminoo.linkpc.net/7095091099097097/Manhattan-Millionaire-s-Cinderella-by-Sun-Chara.pdf