Malicious PDF — malware analysis report

Static analysis result for SHA-256 caa6c5c250ae2ae4…

MALICIOUS

PDF

17.8 KB Created: 2019-05-02 01:21:39 +01:00 Authoring application: mPDF 5.7
MD5: 7ffe29787b1a1ea29e4ac429ad00631f SHA-1: a08e306bb0f529d22798989d69a8235fed78cb36 SHA-256: caa6c5c250ae2ae4cc1f49671e67258175ca98e1416e8c5f6156a9c3918e71ab
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF documents hosted on loaminoo.linkpc.net. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a link farm or SEO spamming operation, which can be a precursor to malicious activity. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/4097096095098097/Return-Of-The-Witch-Detective-Marcella-Witch-s-series-9-by-Dana-E-Donovan.pdf
    • http://loaminoo.linkpc.net/4096094099092090/Eye-of-the-Witch-by-Dana-E-Donovan.pdf
    • http://loaminoo.linkpc.net/4097096095098095/Call-of-the-Witch-Tony-Marcella-Mysteries-7-by-Dana-E-Donovan.pdf
    • http://loaminoo.linkpc.net/2099095092091093/Donovan-s-Angel-Donovan-s-of-the-Delta-1-by-Peggy-Webb.pdf
    • http://loaminoo.linkpc.net/4091097095097095/Water-Witch-Blood-Witch-Bone-Witch-Witches-of-Etlantium-1-3-by-Thea-Atkinson.pdf
    • http://loaminoo.linkpc.net/2097093092094092/Footprints-in-the-Sand-A-Piper-Donovan-Mystery-Piper-Donovan-Wedding-Cake-Mysteries-Book-3-by-Mary-Jane-Clark.pdf
    • http://loaminoo.linkpc.net/6098094099098095/Meurtre-Heron-s-Cove-T1---S-rie-Emma-Sharpe-et-Colin-Donovan-Emma-Sharpe-amp-Colin-Donovan-by-Carla-Neggers.pdf
    • http://loaminoo.linkpc.net/1091090090099099093/Witch-Children-From-Salem-Witch-Hunts-to-Modern-Courtrooms-by-Hans-Sebald.pdf
    • http://loaminoo.linkpc.net/1091099094099099/The-Briley-Witch-Chronicles-Books-1-and-2-The-Spirit-of-a-Witch-Storm-Grey-by-Sarah-Jane-Avory.pdf
    • http://loaminoo.linkpc.net/3097096098096093/Witch-Is-When-Things-Fell-Apart-A-Witch-P-I-Mystery-4-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098096092/Witch-is-When-The-Bubble-Burst-A-Witch-P-I-Mystery-5-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098095091/We-Witch-You-A-Merry-Christmas-A-Witch-P-I-Mystery-5-5-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098096095/Witch-Is-When-Life-Got-Complicated-A-Witch-P-I-Mystery-2-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098094093/Witch-Is-Why-The-Wolf-Howled-A-Witch-P-I-Mystery-18-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098096091/Witch-is-When-The-Penny-Dropped-A-Witch-P-I-Mystery-6-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/3097096098094092/Witch-Is-Why-The-Music-Stopped-A-Witch-P-I-Mystery-19-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/2090096099096/My-Favorite-Witch-Accidental-Witch-Trilogy-2-by-Annette-Blair.pdf
    • http://loaminoo.linkpc.net/1096099092095095/Sex-and-the-Psychic-Witch-Triplet-Witch-Trilogy-1-by-Annette-Blair.pdf
    • http://loaminoo.linkpc.net/3097096098095098/Witch-Is-When-The-Hammer-Fell-A-Witch-P-I-Mystery-8-by-Adele-Abbott.pdf
    • http://loaminoo.linkpc.net/5095096099096090/The-Return-of-the-Witch-The-Witch-s-Daughter-2-by-Paula-Brackston.pdf
    • http://loaminoo.linkpc.net/6098094099098095/Meurtre-Heron-s-Cove-T1---S-rie-Emma-Sharpe-et-Colin-Donovan-Emma-Sharpe-amp-Colin-Donovan-by-Carla-Neggers.pd