Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2a32f569f0048c3…

MALICIOUS

PDF

16.1 KB Created: 2019-04-30 02:41:03 +01:00 Authoring application: mPDF 5.7
MD5: 54e38f557d98415a910ed58db4e109e6 SHA-1: 5e572ff07f797ec5cbfd90588f3e1e5f332ec0ba SHA-256: c2a32f569f0048c3fd96817bbb36bfa118c4aa2b4a9dec4aad2da1dfa3cce5ce
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a PDF_SEO_LINK_FARM heuristic. These URLs point to various book titles hosted on loaminoo.linkpc.net. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly to manipulate search engine results or to serve as a lure for further malicious activity. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific payload.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6098095098097095/Romancing-Lady-Cecily-Romancing-0-5-by-Ashley-March.pdf
    • http://loaminoo.linkpc.net/2093095093095096/Romancing-the-Wrong-Twin-Romancing-the-1-by-Clare-London.pdf
    • http://loaminoo.linkpc.net/2092097096096095/The-Widow-Next-Door-Learning-to-live-again-as-a-young-widow-and-single-mom-after-losing-my-husband-to-suicide-by-Heather-Cruz.pdf
    • http://loaminoo.linkpc.net/2094099096097093/Romancing-the-Mob-Boss-Romancing-the-Mob-Boss-1-by-Mallory-Monroe.pdf
    • http://loaminoo.linkpc.net/3092093097090094/Romancing-the-Mob-Boss-Romancing-the-Mob-Boss-1-by-Mallory-Monroe.pdf
    • http://loaminoo.linkpc.net/7093093090096092/The-Medici-Aesop-Spencer-MS-50-from-the-Spencer-Collection-of-the-New-York-Public-Library-by-Aesop.pdf
    • http://loaminoo.linkpc.net/4092095096098/The-Widow-Makers-The-Widow-Makers-1-by-Jean-Mead.pdf
    • http://loaminoo.linkpc.net/4093099098096095/Romancing-The-Snow-by-Darren-G-Burton.pdf
    • http://loaminoo.linkpc.net/5093099091092098/Romancing-the-Singer-by-Cami-Checketts.pdf
    • http://loaminoo.linkpc.net/1092097094099096/Romancing-the-Grinch-by-Tamara-Philip.pdf
    • http://loaminoo.linkpc.net/4091091095099094/Romancing-Mister-Bridgerton-by-Julia-Quinn.pdf
    • http://loaminoo.linkpc.net/1090091097094/Romancing-the-Duke-Castles-Ever-After-1-by-Tessa-Dare.pdf
    • http://loaminoo.linkpc.net/4096098099093093/Romancing-The-Guardian-Shifters-and-Lovers-2-by-Ali-Atwood.pdf
    • http://loaminoo.linkpc.net/2090094096092092/Romancing-the-Scot-The-Pennington-Family-1-by-May-McGoldrick.pdf
    • http://loaminoo.linkpc.net/2094099091099099/Romancing-the-M-D-Hopewell-General-3-by-Maureen-Smith.pdf
    • http://loaminoo.linkpc.net/4094092095095098/Barbarian-Bride-Romancing-the-Romans-2-by-Eva-Scott.pdf
    • http://loaminoo.linkpc.net/8092097099095/Romancing-Miss-Bront-by-Juliet-Gael.pdf
    • http://loaminoo.linkpc.net/2091097090097090/The-Hotter-They-Come-Romancing-the-Seas-1-by-Roxanne-D-Howard.pdf
    • http://loaminoo.linkpc.net/3091096099092098/Romancing-the-Duke-Castles-Ever-After-1-by-Tessa-Dare.pdf
    • http://loaminoo.linkpc.net/3090094093090099/Romancing-the-Professor-by-Ruby-Moon-Houldson.pdf
    • http://loaminoo.linkpc.net/509