Malicious PDF — malware analysis report

Static analysis result for SHA-256 23546103659c21e7…

MALICIOUS

PDF

17.5 KB Created: 2019-04-30 03:30:05 +01:00 Authoring application: mPDF 5.7
MD5: e481ca1f1f1cc11cf0dd639fa9bdee39 SHA-1: 0ba3fe1c32d14f0023fb6ec4f5df9d2a0d3181d0 SHA-256: 23546103659c21e7cce0506160598046ef7e9f457d23adb9c5fffd1633df18ab
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While the SE_URGENCY_LURE heuristic suggests a potential social engineering component, the primary observed behavior is the mass linking. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure. The IOCs are the URLs found within the document.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2097097093090091/Lassoed-in-Texas-Trilogy-Lassoed-in-Texas-1-3-by-Mary-Connealy.pdf
    • http://loaminoo.linkpc.net/1095091092098090/Gingham-Mountain-Lassoed-in-Texas-3-by-Mary-Connealy.pdf
    • http://loaminoo.linkpc.net/2093094099092098/Petticoat-Ranch-Lassoed-in-Texas-1-by-Mary-Connealy.pdf
    • http://loaminoo.linkpc.net/2095095095098091/Texas-Destiny-Texas-Glory-Texas-Splendor-Leigh-Brothers-Texas-Trilogy-1-3-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/2097090097096096/Swept-Away-Trouble-in-Texas-1-by-Mary-Connealy.pdf
    • http://loaminoo.linkpc.net/2095095093097094/Texas-Glory-Leigh-Brothers-Texas-Trilogy-2-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/2093090094097090/Texas-Glory-Leigh-Brothers-Texas-Trilogy-2-by-Lorraine-Heath.pdf
    • http://loaminoo.linkpc.net/4099090095095099/Last-Chance-Reunion-Texas-Cold-Case-Texas-Lost-and-Found-Chance-Texas-4-by-Linda-Conrad.pdf
    • http://loaminoo.linkpc.net/9090096096091/Texas-Fortunes-Trilogy-Texas-Fortunes-Trilogy-1-3-by-Marcia-Gruver.pdf
    • http://loaminoo.linkpc.net/2090090093094098/Heart-of-Texas-Vol-1-Lonesome-Cowboy-Texas-Two-Step-Heart-of-Texas-1-2-by-Debbie-Macomber.pdf
    • http://loaminoo.linkpc.net/4093091096095093/Heart-of-Texas-Vol-2-Caroline-s-Child-Dr-Texas-Heart-of-Texas-3-4-by-Debbie-Macomber.pdf
    • http://loaminoo.linkpc.net/2097097096090099/Texas-Boardinghouse-Brides-Trilogy-Texas-Boardinghouse-Brides-1-3-by-Vickie-McDonough.pdf
    • http://loaminoo.linkpc.net/4097096094095095/A-Match-Made-in-Texas-Deep-in-the-Heart-of-Texas-6-by-Katie-Lane.pdf
    • http://loaminoo.linkpc.net/2095092091092/The-Texas-Renegade-Returns-Texas-Cattleman-s-Club-A-Missing-Mogul-10-by-Charlene-Sands.pdf
    • http://loaminoo.linkpc.net/2098091092093097/Texas-Twist-Texas-Montgomery-Mavericks-4-by-Cynthia-D-39-Alba.pdf
    • http://loaminoo.linkpc.net/3094098091092097/Reckless-in-Texas-Texas-Rodeo-1-by-Kari-Lynn-Dell.pdf
    • http://loaminoo.linkpc.net/1091093091094/Tougher-in-Texas-Texas-Rodeo-3-by-Kari-Lynn-Dell.pdf
    • http://loaminoo.linkpc.net/1092092095099098/To-Catch-a-Texas-Star-Texas-Heroes-3-by-Linda-Broday.pdf
    • http://loaminoo.linkpc.net/1097092093090096/Texas-Two-Step-Whispering-Springs-Texas-1-by-Cynthia-D-39-Alba.pdf
    • http://loaminoo.linkpc.net/1091094095092094091/Texas-Free-The-Tylers-of-Texas-5-by-Janet-Dailey.pdf
    • http://loaminoo.linkpc.net/4099090095095099/Last-Chance-Reunion-Texas-Cold-Case-Texas-Lost-and-