Malicious PDF — malware analysis report

Static analysis result for SHA-256 b433ec1813157aef…

MALICIOUS

PDF

14.7 KB Created: 2019-05-02 17:40:44 +01:00 Authoring application: mPDF 5.7
MD5: 54704f9c10007111f043df82d04225f9 SHA-1: c5acb3fd186635c935c78064b6e97f73f7001fcb SHA-256: b433ec1813157aef308904846f6dca40efa5dde681182fcad9ff585c1fc6c7ba
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links pointing to external PDF documents hosted on the domain 'loaminoo.linkpc.net'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting deeper analysis of the immediate intent beyond link distribution.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2097093097097092/I-Shall-Never-Return-Volume-5-by-Kazuna-Uchida.pdf
    • http://loaminoo.linkpc.net/8092091090096098/The-Power-of-Return-Return-to-Me-That-I-May-Return-to-You-by-John-Goyette.pdf
    • http://loaminoo.linkpc.net/4091098094095097/Star-Wars-Return-of-the-Jedi-Manga-Volume-1-by-Shin-ichi-Hiromoto.pdf
    • http://loaminoo.linkpc.net/4093095090091092/The-Sand-Wars-Volume-Two-Alien-Salute-Return-Fire-Challenge-Met-by-Charles-Ingrid.pdf
    • http://loaminoo.linkpc.net/8090099094095093/Sh-g-To-Is-by-Fuichi-Uchida.pdf
    • http://loaminoo.linkpc.net/1094094099093/In-Between-Miya-by-Yoshiko-Uchida.pdf
    • http://loaminoo.linkpc.net/1094096096092/Mik-amp-the-Prowler-by-Yoshiko-Uchida.pdf
    • http://loaminoo.linkpc.net/2097099096098/Journey-Home-by-Yoshiko-Uchida.pdf
    • http://loaminoo.linkpc.net/6098091091093098/The-Dancing-Tea-Kettle-by-Yoshiko-Uchida.pdf
    • http://loaminoo.linkpc.net/3096099091090092/Desert-Exile-by-Yoshiko-Uchida.pdf
    • http://loaminoo.linkpc.net/6090092096099092/XIII---Volume-21---Return-to-Green-Falls-XIII-by-Yves-Sente.pdf
    • http://loaminoo.linkpc.net/9092093096099091/Inran-Hitoduma-no-Hurin-Kodukuri-club-by-Uchida-Nana.pdf
    • http://loaminoo.linkpc.net/1094093099093/Journey-to-Topaz-A-Story-of-the-Japanese-American-Evacuation-by-Yoshiko-Uchida.pdf
    • http://loaminoo.linkpc.net/5090096095099099/Brokers-of-Empire-Japanese-Settler-Colonialism-in-Korea-1876-1945-by-Jun-Uchida.pdf
    • http://loaminoo.linkpc.net/1098092093093092/Return-to-Newport-Return-to-Me-2-by-A-L-Parks.pdf
    • http://loaminoo.linkpc.net/1091096093090096093/Classic-Jurassic-Park-Volume-5-Return-to-Jurassic-Park-Part-Two-by-Tom-Bierbaum.pdf
    • http://loaminoo.linkpc.net/1098092093094094/The-Return-Return-to-Me-1-by-A-L-Parks.pdf
    • http://loaminoo.linkpc.net/8099090097098090/Chemistry-and-Chemical-Reactivity-Eighth-Edition-Volume-1-Volume-1-by-John-C-Kotz.pdf
    • http://loaminoo.linkpc.net/2095090090098093/Bomaw-Volume-Two-The-Beauty-Of-Man-And-Woman-Volume-2-by-Mercedes-Keyes.pdf
    • http://loaminoo.linkpc.net/2095092096090095/Daredevil-Volume-14-The-Devil-Inside-and-Out-Volume-1-by-Ed-Brubaker.pdf
    • http://loaminoo.linkpc.net/1094093099093/Journey-to-Topaz-A-Story-of-the-Japanese-American-Evacuation-by-