Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee9ec126777c625e…

MALICIOUS

PDF

17.1 KB Created: 2019-04-30 09:03:10 +01:00 Authoring application: mPDF 5.7
MD5: 882ac8c4d50202e21b325f964955a3f0 SHA-1: 53f3441cfe793af1b4ea2e4abbbef6926bd8918f SHA-256: ee9ec126777c625e9f506e741da1d75f55221d654ce0fd04bd4b9374d9f49e2a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, constituting a link farm. The heuristic 'PDF_SEO_LINK_FARM' indicates that these links are likely generated for SEO purposes, aiming to drive traffic to the 'loaminoo.linkpc.net' domain. While no scripts were extracted, the sheer volume of links suggests a malicious intent to direct users to potentially harmful content or phishing sites. The document body is heavily obfuscated and unreadable.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2097093098095093/Ask-Me-to-Stay-Homeland-1-by-Elise-K-Ackers.pdf
    • http://loaminoo.linkpc.net/2092090094090094/Ask-Me-to-Stay-Homeland-1-by-Elise-K-Ackers.pdf
    • http://loaminoo.linkpc.net/9097090092094/One-for-the-Road-Road-1-by-Elise-K-Ackers.pdf
    • http://loaminoo.linkpc.net/3094095095093091/If-I-Stay-If-I-Stay-1-by-Gayle-Forman.pdf
    • http://loaminoo.linkpc.net/1090091094099099095/Stay-Dead-Stay-Dead-1-by-Steve-Wands.pdf
    • http://loaminoo.linkpc.net/4090098090096097/Homeland-by-George-Obama.pdf
    • http://loaminoo.linkpc.net/6094096093093/Homeland-and-Other-Stories-by-Barbara-Kingsolver.pdf
    • http://loaminoo.linkpc.net/4094094095092091/The-Homeland-Directive-by-Robert-Venditti.pdf
    • http://loaminoo.linkpc.net/4090097093092097/Saul-s-Game-Homeland-2-by-Andrew-Kaplan.pdf
    • http://loaminoo.linkpc.net/4091094097/Best-State-Ever-A-Florida-Man-Defends-His-Homeland-by-Dave-Barry.pdf
    • http://loaminoo.linkpc.net/2095092093094094/The-Ultimates-Volume-2-Homeland-Security-by-Mark-Millar.pdf
    • http://loaminoo.linkpc.net/7092092090094095/A-Photographic-Journey-of-my-Homeland-Armenia-by-Vahe-Peroomian.pdf
    • http://loaminoo.linkpc.net/4094091096096094/Joe-Strummer-and-the-Mescaleros-Vision-of-a-Homeland-by-Anthony-Davie.pdf
    • http://loaminoo.linkpc.net/1094099098095097/Homeland-Crown-Family-Saga-1-by-John-Jakes.pdf
    • http://loaminoo.linkpc.net/1090096094092098/Homeland-The-Illustrated-History-of-the-State-of-Israel-by-Marv-Wolfman.pdf
    • http://loaminoo.linkpc.net/1090099099097093090/Rethinking-America-The-Imperial-Homeland-in-the-21st-Century-by-Ida-Susser.pdf
    • http://loaminoo.linkpc.net/3093097097091/Homeland-Forgotten-Realms-The-Dark-Elf-Trilogy-1-Legend-of-Drizzt-1-by-R-A-Salvatore.pdf
    • http://loaminoo.linkpc.net/5090098094091099/Defenseless-Under-the-Night-The-Roosevelt-Years-and-the-Origins-of-Homeland-Security-by-Matthew-Dallek.pdf
    • http://loaminoo.linkpc.net/1090099092097090095/Reform-Without-Justice-Latino-Migrant-Politics-and-the-Homeland-Security-State-by-Alfonso-Gonzales.pdf
    • http://loaminoo.linkpc.net/7094095090094099/Homeland-Security-A-Complete-Guide-to-Understanding-Preventing-and-Surviving-Terrorism-by-Mark-Sauter.pdf
    • http://loaminoo.linkpc.net/2095092093094094/The-Ultim