Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab42c5f52d639d80…

MALICIOUS

PDF

23.6 KB Created: 2019-05-02 17:57:11 +01:00 Authoring application: mPDF 5.7
MD5: ff5739f9986508328dabdb1f76d3ca6c SHA-1: b8a2552d51a6990cd7344c330df0c2009a6e13aa SHA-256: ab42c5f52d639d8022347ecf7bd566adc5fcd293bd60db69571f7f9811d1f282
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a redirection scheme, potentially used to distribute malicious content or phish for information. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the immediate payload. The primary IOCs are the numerous URLs pointing to the suspicious domain.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9094097098093097/Hell-The-Final-Destination-For-Unbelievers-by-Don-Stewart.pdf
    • http://loaminoo.linkpc.net/1091090095093095096/Destination-Resilience-Challenges-and-Opportunities-for-Destination-Management-and-Governance-by-Elisa-Innerhofer.pdf
    • http://loaminoo.linkpc.net/1091093099091095092/The-Potential-of-Cross-Marketing-for-the-Destination-Management-Organizations-of-New-York-City-and-New-York-State-by-Yvonne-Koppen.pdf
    • http://loaminoo.linkpc.net/1092097097090092/Andorra-by-Peter-Cameron.pdf
    • http://loaminoo.linkpc.net/2097092098090090/The-Weekend-by-Peter-Cameron.pdf
    • http://loaminoo.linkpc.net/4096095093094095/Coral-Glynn-by-Peter-Cameron.pdf
    • http://loaminoo.linkpc.net/1090095099090099/Someday-This-Pain-Will-Be-Useful-to-You-by-Peter-Cameron.pdf
    • http://loaminoo.linkpc.net/5090090099097094/Coral-Glynn-by-Peter-Cameron.pdf
    • http://loaminoo.linkpc.net/1091095090098093090/Aquamarine-Final-Tales-of-the-Revolution-by-Peter-Pessl.pdf
    • http://loaminoo.linkpc.net/3090096092098096/X-Force-Volume-2-Final-Chapter-by-Peter-Milligan.pdf
    • http://loaminoo.linkpc.net/8092092091098090/Combinatorics-Topics-Techniques-Algorithms-by-Peter-J-Cameron.pdf
    • http://loaminoo.linkpc.net/3097096090091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/4098093094096091/City-of-Bones-City-of-Ashes-City-of-Glass-City-of-Fallen-Angels-City-of-Lost-Souls-The-Mortal-Instruments-1-5-by-Cassandra-Clare.pdf
    • http://loaminoo.linkpc.net/1099095097090094/Final-Death-The-Final-Life-3-by-Rose-Garcia.pdf
    • http://loaminoo.linkpc.net/7092099095092095/Superman-The-Final-Days-of-Superman-by-Peter-J-Tomasi.pdf
    • http://loaminoo.linkpc.net/3097091098098095/City-of-Dreadful-Night-by-Peter-Guttridge.pdf
    • http://loaminoo.linkpc.net/7092097090099097/Liverpool-A-City-that-Dared-to-Fight-by-Peter-Taaffe.pdf
    • http://loaminoo.linkpc.net/8097090094091099/Bely-Joyce-and-D-blin-Peripatetics-in-the-City-Novel-by-Peter-I-Barta.pdf
    • http://loaminoo.linkpc.net/1091090095095096095/La-guia-final-compra-y-venta-de-criptomonedas-Salir-a-flote-de-la-bancarrota-1-Que-son-las-criptomonedas-The-final-guide-purchase-and-sale-of-cryptocurrencies-of-bankruptcy-1-What-are-by-Antonio-Rafael-Figueroa-Nasra.pdf
    • http://loaminoo.linkpc.net/1091090095095096093/La-guia-final-compra-y-venta-de-criptomonedas-Salir-a-flote-de-la-bancarrota-6-Gana-miles-de-con-2-criptomonedas-invirtiendo-poco-The-final-guide-buying-Come-out-of-1-by-Antonio-Rafael-Figueroa-Nasra.pdf
    • http://loaminoo.linkpc.net/5090090099097094/Coral-G