Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0ad9a57935cb8c4…

MALICIOUS

PDF

25.9 KB Created: 2019-05-02 10:39:42 +01:00 Authoring application: mPDF 5.7
MD5: 78627a0ea7556415827ee1c36b78256c SHA-1: 76700cf4bca23493b6bbd88bd285b33d38b940e0 SHA-256: c0ad9a57935cb8c400605ec8c9e28c7704620aa3c377821600394a8660f62f0e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links all point to URLs hosted on 'loaminoo.linkpc.net', suggesting a coordinated effort to distribute content or redirect users. While the document body is unreadable, the heuristic strongly suggests a link farm attack pattern. The primary IOCs are the URLs identified in the link farm.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7091098097093094/Ancient-Rome-History-of-a-civilization-that-ruled-the-world-by-Annamaria-Liberati.pdf
    • http://loaminoo.linkpc.net/7091098097092093/Ancient-Rome-History-of-a-Civilization-That-Ruled-the-World-by-Anna-Maria-Liberati.pdf
    • http://loaminoo.linkpc.net/4094098097098095/Rome-A-Fold-Out-History-of-the-Ancient-Civilization-by-Leigh-Grant.pdf
    • http://loaminoo.linkpc.net/5090097090096/The-History-of-the-Ancient-World-From-the-Earliest-Accounts-to-the-Fall-of-Rome-by-Susan-Wise-Bauer.pdf
    • http://loaminoo.linkpc.net/4098096099096098/World-History-Ancient-History-United-States-History-European-Native-American-Russian-Chinese-Asian-Indian-and-Australian-History-Wars-including-World-War-1-and-2-by-Adam-Brown.pdf
    • http://loaminoo.linkpc.net/1091099090093099/The-Wedding-Shroud---A-Tale-of-Ancient-Rome-Tales-of-Ancient-Rome-1-by-Elisabeth-Storrs.pdf
    • http://loaminoo.linkpc.net/9094096099093091/Sino-Iranica-Chinese-Contributions-to-the-History-of-Civilization-in-Ancient-Iran-by-Berthold-Laufer.pdf
    • http://loaminoo.linkpc.net/2096093094097090/SPQR-A-History-of-Ancient-Rome-by-Mary-Beard.pdf
    • http://loaminoo.linkpc.net/2095094096091094/SPQR-A-History-of-Ancient-Rome-by-Mary-Beard.pdf
    • http://loaminoo.linkpc.net/4090092092096096/The-Assassination-of-Julius-Caesar-A-People-s-History-of-Ancient-Rome-by-Michael-Parenti.pdf
    • http://loaminoo.linkpc.net/2093099094098098/The-Lost-Civilization-Enigma-A-New-Inquiry-Into-the-Existence-of-Ancient-Cities-Cultures-and-Peoples-Who-Pre-Date-Recorded-History-by-Philip-Coppens.pdf
    • http://loaminoo.linkpc.net/9091099090095090/Empires-The-Logic-of-World-Domination-from-Ancient-Rome-to-the-United-States-by-Herfried-M-nkler.pdf
    • http://loaminoo.linkpc.net/7097090093097091/Ancient-Roman-Physicians-Galen-Marcellus-Empiricus-Medical-Community-of-Ancient-Rome-Sextus-Empiricus-Ancient-Greek-Medicine-by-Source-Wikipedia.pdf
    • http://loaminoo.linkpc.net/1091099096097097097/A-History-of-the-End-of-the-World-How-the-Most-Controversial-Book-in-the-Bible-Changed-the-Course-of-Western-Civilization-by-Jonathan-Kirsch.pdf
    • http://loaminoo.linkpc.net/7098094097090096/The-Ancient-Maya-and-Their-City-of-Tulum-Uncovering-the-Mysteries-of-an-Ancient-Civilization-and-Their-City-of-Grandeur-by-Bonnie-Bley.pdf
    • http://loaminoo.linkpc.net/3098095095091090/Warfare-in-the-Classical-World-An-Illustrated-Encyclopedia-of-Weapons-Warriors-and-Warfare-in-the-Ancient-Civilizations-of-Greece-and-Rome-by-John-Warry.pdf
    • http://loaminoo.linkpc.net/1090093095098090/Four-Seasons-in-Rome-On-Twins-Insomnia-and-the-Biggest-Funeral-in-the-History-of-the-World-by-Anthony-Doerr.pdf
    • http://loaminoo.linkpc.net/5094090099093094/World-History-of-Ancient-Civilizations-by-McDougal-Littell.pdf
    • http://loaminoo.linkpc.net/2090099097091091/History-Alive-The-Ancient-World-by-Wendy-Frey.pdf
    • http://loaminoo.linkpc.net/5091096090091094/Rome-before-Avignon-A-Social-History-of-Thirteenth-Century-Rome-by-Robert-Brentano.pdf