Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1c67252368292c6…

MALICIOUS

PDF

28.0 KB Created: 2019-04-30 07:03:43 +01:00 Authoring application: mPDF 5.7
MD5: 557b21ec15ac0e6dedfdaacd7e270dda SHA-1: fc32b34cf9d57d5d80c8a7b7d8b355c11d2ed304 SHA-256: b1c67252368292c68b0604076a3aeb63738afa2398ba62e34ca9b1fced8711e3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, primarily hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a redirection mechanism designed to lead users to potentially malicious content. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine the exact user-facing lure. The primary technique observed is the mass distribution of external links.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.li
    • http://loaminoo.linkpc.net/3097096090092091/Joseph-s-Surprise-Gifts-Joseph-Land-2-by-J-Hale-Turner.pdf
    • http://loaminoo.linkpc.net/3097097094095095/Land-Under-England-by-Joseph-O-39-Neill.pdf
    • http://loaminoo.linkpc.net/1095094098093093/Land-under-England-by-Joseph-O-39-Neill.pdf
    • http://loaminoo.linkpc.net/9092097096096099/A-Noble-Priest-Joseph-Salzmann-D-D-Founder-of-the-Salesianum-by-Joseph-Rainer.pdf
    • http://loaminoo.linkpc.net/5099098095090/People-Of-The-Land-Legends-Of-The-Four-Host-First-Nations-by-Tewanee-Joseph.pdf
    • http://loaminoo.linkpc.net/2093099094093093/Cannibals-Shocking-True-Tales-of-the-Last-Taboo-on-Land-and-at-Sea-by-Joseph-Cummins.pdf
    • http://loaminoo.linkpc.net/8091097091093093/Heart-of-Darkness-by-Joseph-Conrad-Illustrated-Heart-of-Darkness-1899-is-a-short-novel-by-Polish-novelist-Joseph-Conrad-by-Joseph-Conrad.pdf
    • http://loaminoo.linkpc.net/1090093091099096094/Zur-Reifizierung-Des-Sexuellen-Im-19-Jahrhundert-Der-Beginn-Einer-Scientia-Sexualis-Dargestellt-Anhand-Dreier-Texte-Von-Hermann-Joseph-Loewenstein-Joseph-Haeussler-Und-Heinrich-Kaan-by-Philipp-Gutmann.pdf
    • http://loaminoo.linkpc.net/9091098094093094/Carl-Joseph-von-Trotta-in-Joseph-Roths-quot-Radetzkymarsch-quot---eine-sp-te-Heldenfigur-by-Andreas-Lehmann.pdf
    • http://loaminoo.linkpc.net/6091098092093099/Le-roman-de-Tristan-et-Iseut-Illustr-et-annot-Version-moderne-renouvel-e-par-Joseph-B-dier-et-annot-e-par-Ferdinand-Bruneti-re-by-Joseph-B-dier.pdf
    • http://loaminoo.linkpc.net/6094094094097094/Celebrating-The-Ministry-Of-Healing-Joseph-Cardinal-Bernardin-s-Reflections-On-Health-Care-by-Joseph-Bernardin.pdf
    • http://loaminoo.linkpc.net/1090098092092098097/Joseph-Haydn-Bericht-Uber-Den-Internationalen-Joseph-Haydn-Kongress-Wien-Hofburg-5--12-September-1982-Proceedings-of-the-Inte-by-Eva-Badura-Skoda.pdf
    • http://loaminoo.linkpc.net/9091098094094095/Joseph-Roth---Gesammelte-Werke-Romane-Erz-hlungen-Journalistische-Schriften-mehr-als-30-Titel-in-einem-E-Book---Radetzkymarsch-Hiob-Die-Kapuzinergruft-Trinker-Das-falsche-Gewic-by-Joseph-Roth.pdf
    • http://loaminoo.linkpc.net/9094098098090096/Trial-of-Joseph-B-rub-and-C-sar-e-Th-riault-his-wife-by-Joseph-B-rub-.pdf
    • http://loaminoo.linkpc.net/5098092092098090/Joseph-Retinger---Memoirs-of-an-Eminence-Grise-by-Joseph-Hieronim-Retinger.pdf
    • http://loaminoo.linkpc.net/2099093091090099/Precious-Gifts-Baby-Makes-Three-3-by-Dawn-M-Turner.pdf
    • http://loaminoo.linkpc.net/6093095095097090/The-Book-of-Mormon-An-Account-Written-by-the-Hand-of-Mormon-Upon-Plates-Taken-from-the-Plates-of-Nephi-Tr-by-Joseph-Smith-Division-Into-Chapters-and-Verses-with-References-by-Orson-Pratt-by-Joseph-Smith-Jr-.pdf
    • http://loaminoo.linkpc.net/5093095096092096/Pensees-and-Letters-of-Joseph-Joubert-by-Joseph-Joubert.pdf
    • http://loaminoo.linkpc.net/6095091098099099/Heart-of-Darkness-Joseph-Conrad-by-Joseph-Conrad.pdf
    • http://loaminoo.linkpc.net/9094097094098096/Catch-22-Joseph-Heller-by-Joseph-Heller.pdf