Malicious PDF — malware analysis report

Static analysis result for SHA-256 1df5a9b947f05163…

MALICIOUS

PDF

21.7 KB Created: 2019-04-30 04:35:27 +01:00 Authoring application: mPDF 5.7
MD5: 9517178273f845937b118b7c22813afb SHA-1: 3c452d7ac065bad86d8193bea48c8901dfc685b6 SHA-256: 1df5a9b947f051637def448805fb53bd2e3f506a8b0286595dd9d81a02ae127e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to external PDF documents, a technique often used for SEO spam or to redirect users to malicious sites. The heuristic PDF_SEO_LINK_FARM indicates a mass external link farm. While the URLs themselves are currently marked as benign, the sheer volume and the use of a dynamic DNS domain suggest a malicious intent to distribute content or phish for information. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/8095095098098/A-Storm-of-Swords-Part-1-Steel-and-Snow-A-Song-of-Ice-and-Fire-3-part-1-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/8095098092096/A-Storm-of-Swords-Part-2-Blood-and-Gold-A-Song-of-Ice-and-Fire-3-part-2-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/6092095097095/A-Storm-of-Swords-Blood-and-Gold-A-Song-of-Ice-and-Fire-3-Part-2-of-2-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/2097098096094094/The-George-R-R-Martin-Song-Of-Ice-and-Fire-Box-Set-featuring-A-Game-of-Thrones-A-Clash-of-Kings-A-Storm-of-Swords-and-A-Feast-for-Crows-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/6090099096092/A-Storm-of-Swords-A-Song-of-Ice-and-Fire-3-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/1098095097093090/A-Storm-of-Swords-A-Song-of-Ice-and-Fire-3-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/2092092091090097/A-Storm-of-Swords-A-Song-of-Ice-and-Fire-3-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/5095098094093097/Games-of-Thrones-A-Storm-of-Swords-Book-Three-of-a-Song-of-Ice-and-Fire-Vol-3c-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/6091091093097091/Krallar-n-arp-mas-K-s-m-II-A-Song-of-Ice-and-Fire-2-part-2-of-2-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/3096095091093/A-Dance-with-Dragons-2-After-the-Feast-A-Song-of-Ice-and-Fire-5-Part-2-of-2-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/2092092090097094/A-Dance-with-Dragons-Dreams-and-Dust-A-Song-of-Ice-and-Fire-5-part-1-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/9096090099093092/A-Game-of-Thrones-4-Book-Bundle-A-Song-of-Ice-and-Fire-Series-A-Game-of-Thrones-A-Clash-of-Kings-A-Storm-of-Swords-and-A-Feast-for-Crows-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/2094090091099090/Eisenthron-A-Song-of-Ice-and-Fire-1-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/6098091091099/A-Game-of-Thrones-A-Song-of-Ice-and-Fire-1-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/1097091095090093/A-Dance-with-Dragons-A-Song-of-Ice-and-Fire-5-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/4098094091090/A-Dream-of-Spring-A-Song-of-Ice-and-Fire-7-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/5098096094090/A-Clash-of-Kings-A-Song-of-Ice-and-Fire-2-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/2096092094093/A-Game-of-Thrones-A-Song-of-Ice-and-Fire-1-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/5096096094092098/A-Game-of-Thrones-A-Song-of-Ice-and-Fire-1-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/6090098091095/A-Game-of-Thrones-A-Song-of-Ice-and-Fire-1-by-George-R-R-Martin.pdf
    • http://loaminoo.linkpc.net/2097098096094094/The-George-R-R-Martin-Song-Of-Ice-and-Fire-Box-Set-featuring