Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb23584558a0a8d9…

MALICIOUS

PDF

16.5 KB Created: 2019-04-30 06:51:07 +01:00 Authoring application: mPDF 5.7
MD5: 438eec7440c455e61611b51d480ee082 SHA-1: 8904881d06a8996bebf9b13391e3cf9d03d1edad SHA-256: eb23584558a0a8d926679f38433bee77f561d1bc877fe639a2d3772033e22c94
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF documents, hosted on the domain loaminoo.linkpc.net. This behavior is indicative of a link farm or SEO spam campaign, designed to drive traffic to a specific set of URLs. The document body was not sufficiently parsable to determine a more specific lure, but the sheer volume of links suggests a malicious intent to direct users to potentially harmful content or exploit kits.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7093097095093092/Rules-of-Accusation-by-Paula-M-Block.pdf
    • http://loaminoo.linkpc.net/9096095094094099/Rules-of-Shanit-The-Divine-Rules-for-Followers-of-Shani-Sanatan-Dharma-Where-there-is-God--there-is-a-Way-by-Anurag-Kartik.pdf
    • http://loaminoo.linkpc.net/8097097090091095/If-Life-Is-a-Game-These-Are-the-Rules-Ten-Rules-for-Being-Human-as-Introduced-in-Chicken-Soup-for-the-Soul-by-Cherie-Carter-Scott.pdf
    • http://loaminoo.linkpc.net/1098090090094096/The-Rules-for-Breaking-The-Rules-for-Disappearing-2-by-Ashley-Elston.pdf
    • http://loaminoo.linkpc.net/3099094090097099/The-Rules-II-More-Rules-to-Live-and-Love-By-by-Ellen-Fein.pdf
    • http://loaminoo.linkpc.net/4099090095099096/The-Fighter-s-Block-The-Fighter-s-Block-1-by-Hadley-Quinn.pdf
    • http://loaminoo.linkpc.net/9091094090092/The-Fighter-s-Block-The-Fighter-s-Block-1-by-Hadley-Quinn.pdf
    • http://loaminoo.linkpc.net/2096097093095097/The-Accusation-by-Bandi.pdf
    • http://loaminoo.linkpc.net/2095090092097090/The-Accusation-by-Bandi.pdf
    • http://loaminoo.linkpc.net/7093097095092093/Accusation-by-Catherine-Bush.pdf
    • http://loaminoo.linkpc.net/7093097095092094/The-Accusation-by-Zosia-Wand.pdf
    • http://loaminoo.linkpc.net/7093097095093093/The-Way-of-Humility-Corruption-and-Sin-On-Self-Accusation-by-Pope-Francis.pdf
    • http://loaminoo.linkpc.net/7093097098091095/Pathology-of-Lying-Accusation-and-Swindling-by-William.pdf
    • http://loaminoo.linkpc.net/2099095095098/Paula-Deen-39-s-Southern-Cooking-Bible-by-Paula-H-Deen.pdf
    • http://loaminoo.linkpc.net/3097092091093090/Amelia-Rules-Volume-2-What-Makes-You-Happy-Amelia-Rules-2-by-Jimmy-Gownley.pdf
    • http://loaminoo.linkpc.net/3097091099094091/Amelia-Rules-Volume-1-The-Whole-World-s-Crazy-Amelia-Rules-1-by-Jimmy-Gownley.pdf
    • http://loaminoo.linkpc.net/7093097098097097/Erasing-the-Accusation-of-Shirk-A-Dialogue-with-a-Kharajite-by-Abu-Ammar.pdf
    • http://loaminoo.linkpc.net/7093097098090094/Accusation-or-The-family-of-D-Anglade-by-John-Howard-Payne.pdf
    • http://loaminoo.linkpc.net/5092098094/The-Accusation-Forbidden-Stories-from-Inside-North-Korea-by-Bandi.pdf
    • http://loaminoo.linkpc.net/2093097093091098/AIDS-and-Accusation-Haiti-and-the-Geography-of-Blame-by-Paul-Farmer.pdf
    • http://loaminoo.linkpc.net/9091094090092/The-Fighter-s-Block-The-Fighter-s-Block-1-