Malicious PDF — malware analysis report

Static analysis result for SHA-256 a31699684a3537ec…

MALICIOUS

PDF

21.8 KB Created: 2019-05-02 01:44:16 +01:00 Authoring application: mPDF 5.7
MD5: 82a590936809f68070e867c925d36e75 SHA-1: cb52527b27dbf3635f8a9ccdb02084e11c0ca444 SHA-256: a31699684a3537ec14e25712c674a447eac91685a6a6b21b9d6f32012410ea35
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, all hosted on the domain 'loaminoo.linkpc.net'. This pattern is indicative of a link farm or a redirection scheme, likely intended to direct users to malicious content or phishing sites. While the specific payload is not directly executed by this PDF, the extensive linking suggests a malicious intent to lead users to potentially harmful resources. The heuristic 'PDF_SEO_LINK_FARM' strongly supports this assessment.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.ne
    • http://loaminoo.linkpc.net/7096092097093090/Michener-s-South-Pacific-by-Stephen-J-May.pdf
    • http://loaminoo.linkpc.net/1091092093094093099/The-First-South-Pacific-Campaign-Pacific-Fleet-Strategy-December-1941-June-1942-by-John-B-Lundstrom.pdf
    • http://loaminoo.linkpc.net/4095091099090096/Guns-Drugs-and-Coconuts-South-Pacific-and-South-East-Asia-by-John-Frederick-Dixon.pdf
    • http://loaminoo.linkpc.net/7096092097093091/Rascals-in-Paradise-Turbulent-Adventures-and-Bold-Courage-on-the-South-Seas-by-James-A-Michener.pdf
    • http://loaminoo.linkpc.net/6098098092093095/The-Tale-of-South-Pacific-by-Thana-Skouras.pdf
    • http://loaminoo.linkpc.net/2092095096097093/Solomon-Time-Adventures-in-the-South-Pacific-by-Will-Randall.pdf
    • http://loaminoo.linkpc.net/4095098090095095/The-South-Pacific-Murders-A-Mia-Ferrari-Mystery-3-by-Sylvia-Massara.pdf
    • http://loaminoo.linkpc.net/5091091096096090/Representing-the-South-Pacific-Colonial-Discourse-from-Cook-to-Gauguin-by-Rod-Edmond.pdf
    • http://loaminoo.linkpc.net/9090097091094/Hawaii-text-only-by-J-A-Michener-by-James-A-Michener.pdf
    • http://loaminoo.linkpc.net/3097091093095091/The-Ghost-Mountain-Boys-Their-Epic-March-and-the-Terrifying-Battle-for-New-Guinea--The-Forgotten-War-of-the-South-Pacific-by-James-Campbell.pdf
    • http://loaminoo.linkpc.net/1095090093094093/My-South-My-Soul-Vol-1-by-Stephen-Friend.pdf
    • http://loaminoo.linkpc.net/7095093096097096/Martin-Meursault-s-Enjoy-The-Authoritative-Guide-To-The-Restaurants-Of-The-Monterey-Peninsula-Including-Carmel-Monterey-Pacific-Grove-Pebble-Beach-Marina-Seaside-Carmel-Valley-The-South-Coast-And-Beyond-by-Martin-Meursault.pdf
    • http://loaminoo.linkpc.net/2095094098094091/The-South-vs-The-South-How-Anti-Confederate-Southerners-Shaped-the-Course-of-the-Civil-War-by-William-W-Freehling.pdf
    • http://loaminoo.linkpc.net/1098099091097099/A-Single-Swallow-Following-An-Epic-Journey-From-South-Africa-To-South-Wales-by-Horatio-Clare.pdf
    • http://loaminoo.linkpc.net/1091098091090090093/Far-East-Down-South-Asians-in-the-American-South-by-Raymond-A-Mohl.pdf
    • http://loaminoo.linkpc.net/7096092099090096/Social-Psychology-by-Michener.pdf
    • http://loaminoo.linkpc.net/1090094097091098/Iberia-by-James-A-Michener.pdf
    • http://loaminoo.linkpc.net/2094090095090091/Sayonara-by-James-A-Michener.pdf
    • http://loaminoo.linkpc.net/4097093099099097/The-Drifters-by-James-A-Michener.pdf
    • http://loaminoo.linkpc.net/7096092098091097/Matecumbe-by-James-A-Michener.pdf