Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8491d26d3ba16ed…

MALICIOUS

PDF

16.4 KB Created: 2019-05-02 17:39:53 +01:00 Authoring application: mPDF 5.7
MD5: 7bbf32404595c3aeea726f4d990becc9 SHA-1: c1dff521f9024825e069bb10ac1a3631d48ef803 SHA-256: c8491d26d3ba16ed6c09b2864c36050a3ab4c5245d98d1f09719c8ddcf1abf0f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a link farm, with 22 external PDF links embedded within the document. These links all point to the same domain, loaminoo.linkpc.net, and appear to be book titles. The presence of a large number of such links suggests a potential attempt to manipulate search engine results or distribute further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/6099092090090090/Accidental-Chemistry-Second-Chances-2-by-Susan-Laine.pdf
    • http://loaminoo.linkpc.net/6099091099094096/After-the-Romance-Novel-Before-and-After-1-by-Susan-Laine.pdf
    • http://loaminoo.linkpc.net/2095096095091098/Sub-Sailor-s-Knot-1-by-Susan-Laine.pdf
    • http://loaminoo.linkpc.net/4095093092099097/The-Sensualist-amp-the-Untouched-by-Susan-Laine.pdf
    • http://loaminoo.linkpc.net/6099092090090093/Sensible-Commitments-Senses-and-Sensations-5-by-Susan-Laine.pdf
    • http://loaminoo.linkpc.net/3093090091096091/The-Wolfing-Way-Lifting-the-Veil-1-by-Susan-Laine.pdf
    • http://loaminoo.linkpc.net/6099091099094091/Hard-amp-Raw-Cowboys-of-Snow-Lake-5-by-Susan-Laine.pdf
    • http://loaminoo.linkpc.net/3099093098092099/Wolfe-and-His-Bunny-Pariah-Pack-1-by-Susan-Laine.pdf
    • http://loaminoo.linkpc.net/4097098093099096/Stars-amp-Stripes-A-Bedtime-Story-Cowboys-of-Snow-Lake-6-by-Susan-Laine.pdf
    • http://loaminoo.linkpc.net/1090097099098091096/Accidental-Mistress-by-Susan-Napier.pdf
    • http://loaminoo.linkpc.net/1090097092091096098/Chemistry-for-Higher-Education-A-Practical-Guide-to-Designing-a-Course-in-Chemistry-by-Jan-H-Apotheker.pdf
    • http://loaminoo.linkpc.net/1091097091091098093/Topics-in-Current-Chemistry-Volume-258-Supramolecular-Dye-Chemistry-by-Frank-W-rthner.pdf
    • http://loaminoo.linkpc.net/6098091092096091/Physical-Inorganic-Chemistry-A-Coordination-Chemistry-Approach-by-S-F-A-Kettle.pdf
    • http://loaminoo.linkpc.net/2096091091094099/The-Accidental-Call-Girl-Accidental-1-by-Portia-Da-Costa.pdf
    • http://loaminoo.linkpc.net/1099095099096095/The-Accidental-Apprentice-Accidental-Magik-1-by-Anika-Arrington.pdf
    • http://loaminoo.linkpc.net/3090091098090092/How-Many-Chances-Chances-2-by-Beverley-Hollowed.pdf
    • http://loaminoo.linkpc.net/2097090090094094/The-Accidental-TV-Star-Accidental-2-by-Emily-Evans.pdf
    • http://loaminoo.linkpc.net/4093098091097099/Accidental-Billionaire-Accidental-5-by-Emily-Evans.pdf
    • http://loaminoo.linkpc.net/2096091091094098/The-Accidental-Mistress-Accidental-2-by-Portia-Da-Costa.pdf
    • http://loaminoo.linkpc.net/9092097099098090/Tropospheric-Chemistry-Results-of-the-German-Tropospheric-Chemistry-Programme-by-W-Seiler.pdf
    • http://loaminoo.linkpc.net/1090097092091096098/Chemistry-for-Higher-Educati