Malicious PDF — malware analysis report

Static analysis result for SHA-256 31f5ca9a16bae9fe…

MALICIOUS

PDF

16.6 KB Created: 2019-05-02 06:13:30 +01:00 Authoring application: mPDF 5.7
MD5: 41ab270980075a1f07898ba2d4c22fb3 SHA-1: e4c17a53b26678bc8a9e2bb4b7030785347362d5 SHA-256: 31f5ca9a16bae9fe24dfca420d091fc9767491c3aded702c03488132d8a89796
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. The primary heuristic indicates this is a critical finding, suggesting the document's purpose is to direct users to numerous external sites. While the document body is heavily corrupted, the presence of these links strongly implies a malicious intent, possibly for SEO manipulation or to serve as a distribution point for further malware. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7098090099099098/In-Quiet-Light-Poems-on-Vermeer-s-Women-by-Marilyn-Chandler-McEntyre.pdf
    • http://loaminoo.linkpc.net/5091098090096098/Vermeer-in-Hell-Poems-by-Michael-White.pdf
    • http://loaminoo.linkpc.net/1091091093094098/The-Women-Of-Plums-Poems-In-The-Voices-Of-Slave-Women-by-Dolores-Kendrick.pdf
    • http://loaminoo.linkpc.net/8090097096094/The-War-Against-Women-by-Marilyn-French.pdf
    • http://loaminoo.linkpc.net/2098099099098098/The-Women-s-Room-by-Marilyn-French.pdf
    • http://loaminoo.linkpc.net/4093098098092098/The-Women-s-Room-by-Marilyn-French.pdf
    • http://loaminoo.linkpc.net/2095097091099097/The-Women-s-Room-by-Marilyn-French.pdf
    • http://loaminoo.linkpc.net/1094099098098/Carver-A-Life-in-Poems-by-Marilyn-Nelson.pdf
    • http://loaminoo.linkpc.net/2090091094095093/Soul-Mouth-Poems-by-Marilyn-Bowering.pdf
    • http://loaminoo.linkpc.net/1095091092094/Homeplace-Poems-by-Marilyn-Nelson-Waniek.pdf
    • http://loaminoo.linkpc.net/2095097092097090/Beyond-Power-On-Women-Men-and-Morals-by-Marilyn-French.pdf
    • http://loaminoo.linkpc.net/4094091099098094/Counting-for-Nothing-What-Men-Value-and-What-Women-are-Worth-by-Marilyn-Waring.pdf
    • http://loaminoo.linkpc.net/1095090094098/The-Fields-of-Praise-New-and-Selected-Poems-by-Marilyn-Nelson.pdf
    • http://loaminoo.linkpc.net/3099094092098093/Hard-Love-Province-Poems-by-Marilyn-Chin.pdf
    • http://loaminoo.linkpc.net/6095095094098098/Complete-Works-of-Johannes-Vermeer-by-Johannes-Vermeer.pdf
    • http://loaminoo.linkpc.net/2098095092095099/From-Eve-to-Dawn-A-History-of-Women-in-the-World-Vol-1-by-Marilyn-French.pdf
    • http://loaminoo.linkpc.net/3091092090091/A-Stranger-s-Mirror-New-and-Selected-Poems-1994-2014-by-Marilyn-Hacker.pdf
    • http://loaminoo.linkpc.net/7090095099099098/Tales-from-Our-Hearts-and-Other-Body-Parts-Women-s-Health-Anthology-by-Marilyn-Cugel.pdf
    • http://loaminoo.linkpc.net/7090096090090091/Tales-from-Our-Hearts-and-Other-Body-Parts-A-Women-s-Health-Anthology-by-Anthologist-Marilyn-Cugel.pdf
    • http://loaminoo.linkpc.net/5098098092095092/Ask-Marilyn-The-Best-of-quot-Ask-Marilyn-quot-Letters-Published-in-Parade-Magazine-from-1986-to-1992-and-Many-More-Never-Before-Published-by-Marilyn-Vos-Savant.pdf
    • http://loaminoo.linkpc.net/1095090094098/The-Fields-of-Praise-New-and-Selected-Poems-by-Marilyn-Nelso