Malicious PDF — malware analysis report

Static analysis result for SHA-256 32831ef9d2d93db3…

MALICIOUS

PDF

18.8 KB Created: 2019-05-02 18:07:46 +01:00 Authoring application: mPDF 5.7
MD5: ff4e511da6728e149d6ff7015fd10681 SHA-1: ba60c7929554317bebd884cc22be9618a380ceb8 SHA-256: 32831ef9d2d93db3b0adacaf9c617a21c31e707c636855afaeb50a5a63c6475e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign content, the sheer volume and the use of a dynamic DNS hostname suggest a potential for malicious redirection or SEO abuse. The document body was not sufficiently extracted to determine a specific lure, but the structure indicates a link farm designed to distribute traffic or manipulate search engine results. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/7098094094091092/Salafi-Jihadism-The-History-of-an-Idea-by-Shiraz-Maher.pdf
    • http://loaminoo.linkpc.net/4092090098092098/Nonviolence-The-History-of-a-Dangerous-Idea-by-Mark-Kurlansky.pdf
    • http://loaminoo.linkpc.net/5092091092098091/Fear-The-History-of-a-Political-Idea-by-Corey-Robin.pdf
    • http://loaminoo.linkpc.net/3097095099095097/The-Idea-of-Israel-A-History-of-Power-and-Knowledge-by-Ilan-Papp-.pdf
    • http://loaminoo.linkpc.net/5094093097096/The-Great-Chain-of-Being-A-Study-of-the-History-of-an-Idea-by-Arthur-O-Lovejoy.pdf
    • http://loaminoo.linkpc.net/9091096094092098/Evil-A-Primer-A-History-of-a-Bad-Idea-from-Beelzebub-to-Bin-Laden-by-William-Hart.pdf
    • http://loaminoo.linkpc.net/9095097097093093/What-Is-Church-History-Vindication-of-the-Idea-of-Historical-Development-by-Philip-Schaf.pdf
    • http://loaminoo.linkpc.net/4095090095099099/Christianity-s-Dangerous-Idea-The-Protestant-Revolution-A-History-from-the-Sixteenth-Century-to-the-Twenty-First-by-Alister-E-McGrath.pdf
    • http://loaminoo.linkpc.net/2093097097091097/Taking-the-Medicine-A-Short-History-of-Medicine-s-Beautiful-Idea-and-our-Difficulty-Swallowing-It-by-Druin-Burch.pdf
    • http://loaminoo.linkpc.net/8095092096094091/Bay-View-An-American-Idea-an-American-Idea-by-Mary-Jane-Doerr.pdf
    • http://loaminoo.linkpc.net/2092098094099/Defenders-of-the-Scroll-by-Shiraz.pdf
    • http://loaminoo.linkpc.net/7095097097092092/Un-Monstruo-Viene-a-Verme-A-Monster-Calls-A-Partir-de-Una-Idea-Original-de-Siobhan-Dowd-Inspired-by-an-Idea-from-Siobhan-Dowd-by-Patrick-Ness.pdf
    • http://loaminoo.linkpc.net/7096095092093095/Hafiz-of-Shiraz-by-David-Cloutier.pdf
    • http://loaminoo.linkpc.net/1095099098097090/The-Septembers-of-Shiraz-by-Dalia-Sofer.pdf
    • http://loaminoo.linkpc.net/6092090096090092/Festival-of-Arts-Shiraz-Persepolis-1970-by-Vali-Mahlouji.pdf
    • http://loaminoo.linkpc.net/3091093093090095/Baby-Daisy-s-Good-Idea-La-Buena-Idea-De-Bebe-Daisy-Baby-s-First-Disney-Books-English-Spanish-by-Walt-Disney-Company.pdf
    • http://loaminoo.linkpc.net/9099094094095091/The-Fields-by-Kevin-Maher.pdf
    • http://loaminoo.linkpc.net/1097090097098097/This-One-Thing-by-Damian-Maher.pdf
    • http://loaminoo.linkpc.net/2093096090093095/Deadline-by-Stephen-Maher.pdf
    • http://loaminoo.linkpc.net/3097096095093098/Grace-and-The-Ghost-by-Estelle-Maher.pdf