Malicious PDF — malware analysis report

Static analysis result for SHA-256 f52d5e58a819320a…

MALICIOUS

PDF

25.7 KB Created: 2019-04-30 05:40:06 +01:00 Authoring application: mPDF 5.7
MD5: 6e0370245a485ee1b766b580509268a3 SHA-1: f4a3fa5dc95dbaa411a7420e4888516b0bdb2779 SHA-256: f52d5e58a819320ae3efa7831788cf3824763de06a23ffd03486a4bb3e431f8b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to a single domain, loaminoo.linkpc.net. This is indicative of a link farm or SEO manipulation tactic. While the URLs themselves are marked as benign, the sheer volume and the nature of the heuristic firing suggest a malicious intent to drive traffic or potentially distribute further payloads. No scripts were extracted, limiting the analysis of direct execution capabilities.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/9098098097092093/Three-Months-in-a-Workshop-A-Practical-Study-by-Paul-Gohre.pdf
    • http://loaminoo.linkpc.net/9098098097091090/Three-Months-In-A-Workshop-A-Practical-Study-by-Paul-G-hre.pdf
    • http://loaminoo.linkpc.net/6092094092092092/Gotham-Writers-Workshop-Writing-Fiction-The-Practical-Guide-from-New-York-s-Acclaimed-Creative-Writing-School-by-Alexander-Steele.pdf
    • http://loaminoo.linkpc.net/2097094098095090/Gotham-Writers-Workshop-Writing-Fiction-The-Practical-Guide-From-New-York-s-Acclaimed-Creative-Writing-School-by-Alexander-Steele.pdf
    • http://loaminoo.linkpc.net/5096093098092095/Fantasy-Workshop-A-Practical-Guide-The-Painting-Techniques-of-Boris-Vallejo-and-Julie-Bell-by-Boris-Vallejo.pdf
    • http://loaminoo.linkpc.net/3098096093093098/Shades-Of-Green-A-mostly-practical-A-Z-for-the-reluctant-environmentalist-by-Paul-Waddington.pdf
    • http://loaminoo.linkpc.net/1091096095099099097/Fundamentals-of-Kalman-Filtering-A-Practical-Approach-by-Paul-Zarchan.pdf
    • http://loaminoo.linkpc.net/2092092094090091/The-Workshop-Seven-Decades-of-the-Iowa-Writers-Workshop---43-Stories-Recollections-amp-Essays-on-Iowa-s-Place-in-Twentieth-Century-American-Literature-by-Tom-Grimes.pdf
    • http://loaminoo.linkpc.net/8099091095099096/Word-Study-Greek-English-New-Testament-NRSV-by-Paul-R-McReynolds.pdf
    • http://loaminoo.linkpc.net/1090097090092096096/Creation-and-Scientific-Creativity-A-Study-in-the-Thought-of-S-L-Jaki-by-Paul-Haffner.pdf
    • http://loaminoo.linkpc.net/2094094097097091/The-BDSM-Studies-Trilogy-Corporal-Punishment-A-Study-in-Caning-Orgasm-Denial-A-Study-in-Chastity-amp-Forced-Feminization-A-Study-in-Sissification-by-Sabrina-Jen-Mountford.pdf
    • http://loaminoo.linkpc.net/8099090096097094/Study-Guide-for-Chemistry-Human-Activity-Chemical-Reactivity-by-Paul-M-Treichel.pdf
    • http://loaminoo.linkpc.net/6097093095099090/Biblical-Narrative-in-the-Philosophy-of-Paul-Ricoeur-A-Study-in-Hermeneutics-and-Theology-by-Kevin-J-Vanhoozer.pdf
    • http://loaminoo.linkpc.net/1091097098090096097/Practical-Guide-To-Teaching-English-Within-The-National-Curriculum-Practical-Guides-Series-by-Bill-Laar.pdf
    • http://loaminoo.linkpc.net/6099093093094096/Nuclear-Matter-in-Different-Phases-and-Transitions-Proceedings-of-the-Workshop-Nuclear-Matter-in-Different-Phases-and-Transitions-March-31-April-10-1998-Les-Houches-France-by-Jean-Paul-Blaizot.pdf
    • http://loaminoo.linkpc.net/1091095099092096090/WALKING-IN-THE-SPIRIT-A-STUDY-OF-PAUL-S-TEACHING-ON-THE-SPIRIT-AND-ETHICS-IN-GALATIANS-by-KWESI-OTOO.pdf
    • http://loaminoo.linkpc.net/6097094092091093/3-Months-Shy-by-Satin.pdf
    • http://loaminoo.linkpc.net/2094093090/Night-Study-Soulfinders-2-Study-5-by-Maria-V-Snyder.pdf
    • http://loaminoo.linkpc.net/8090097098091098/Becoming-a-Mother-From-Birth-to-Six-Months-by-Gro-Nylander.pdf
    • http://loaminoo.linkpc.net/3093093097092098/Three-Months-of-Chaos-by-Alex-Mitchell.pdf
    • http://loaminoo.linkpc.net/5096093098092095/Fantasy-Workshop-A-Practical-Guide-The-Painti