Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1ed477f2652a599…

MALICIOUS

PDF

16.6 KB Created: 2019-05-06 16:38:02 +01:00 Authoring application: mPDF 5.7
MD5: 42218fc5f8aa4eb34b1107e1860b0d94 SHA-1: 7ba57e1673b1244adb26768c7cdfea810d10dd1d SHA-256: d1ed477f2652a599da3a10a1c951d3bb7d0f636b82a36de0557004d6e1c67842
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains a large number of embedded URLs pointing to external PDF files. These URLs are hosted on the dynamic DNS domain 'loaminoo.linkpc.net', suggesting a link farm or redirection scheme. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' which strongly suggests the document's purpose is to drive traffic to these external resources. No scripts were extracted, limiting further analysis of the document's behavior.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/3094097092093096/Mayan-December-by-Brenda-Cooper.pdf
    • http://loaminoo.linkpc.net/8097090092090/Good-Intentions-The-Road-to-Hell-1-by-Brenda-K-Davies.pdf
    • http://loaminoo.linkpc.net/3094099091091090/Live-Right-and-Find-Happiness-Although-Beer-is-Much-Faster-Life-Lessons-and-Other-Ravings-from-Dave-Barry-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/1095090091094096/Paralysed-by-Sherry-Ashworth.pdf
    • http://loaminoo.linkpc.net/1090094098096/I-ll-Mature-When-I-m-Dead-Dave-Barry-s-Amazing-Tales-of-Adulthood-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/3098095097098097/Dave-Barry-s-Money-Secrets-Like-Why-Is-There-a-Giant-Eyeball-on-the-Dollar-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/5091093091098094/The-Night-Visitors-by-Jenn-Ashworth.pdf
    • http://loaminoo.linkpc.net/1091091095097/My-Darling-Caroline-by-Adele-Ashworth.pdf
    • http://loaminoo.linkpc.net/5090090096093096/Miss-Delacourt-Has-Her-Day-by-Heidi-Ashworth.pdf
    • http://loaminoo.linkpc.net/2097093098097091/A-Midwinter-Ball-by-Heidi-Ashworth.pdf
    • http://loaminoo.linkpc.net/4096099096092098/O-er-The-River-Liffey-by-Heidi-Ashworth.pdf
    • http://loaminoo.linkpc.net/3096091095098092/Barry-Trotter-and-the-Shameless-Parody-Barry-Trotter-1-by-Michael-Gerber.pdf
    • http://loaminoo.linkpc.net/2092094093096094/Stolen-Charms-Winter-Garden-1-by-Adele-Ashworth.pdf
    • http://loaminoo.linkpc.net/2090090095090097/Miss-Armistead-Makes-Her-Choice-by-Heidi-Ashworth.pdf
    • http://loaminoo.linkpc.net/1090091096096099099/The-Republic-in-Crisis-1848-1861-by-John-Ashworth.pdf
    • http://loaminoo.linkpc.net/9093092097098/Demon-Soul-Caine-Brothers-1-by-Christine-Ashworth.pdf
    • http://loaminoo.linkpc.net/1090091094092093095/Barry-Maitland-Books-2017-Checklist-Reading-Order-of-Brock-and-Kolla-Mysteries-The-Belltree-Trilogy-and-List-of-All-Barry-Maitland-Books-by-Sorted-Guide.pdf
    • http://loaminoo.linkpc.net/1093092091098098/The-Lord-Who-Sneered-and-Other-Tales-Miss-Delacourt-5-by-Heidi-Ashworth.pdf
    • http://loaminoo.linkpc.net/4098097099098090/Lady-Crenshaw-s-Christmas-Miss-Delacourt-3-by-Heidi-Ashworth.pdf
    • http://loaminoo.linkpc.net/6095095091093/Dave-Barry-s-Complete-Guide-to-Guys-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/20970